NONE · 0

CVE-2026-92627

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a tem...

Vulnerability Description

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-92627?

CVE-2026-92627 is a documented vulnerability. A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a tem...

How severe is CVE-2026-92627?

CVSS scoring is not yet available for CVE-2026-92627. Check NVD for updates.

Is there a patch for CVE-2026-92627?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.