Home

Description

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was allocated by H5D__typeinfo_init_phase3 and freed by H5D__typeinfo_term.

PUBLISHED Reserved 2026-03-30 | Published 2026-04-09 | Updated 2026-04-13 | Assigner GitHub_M




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-416: Use After Free

Product status

<= 1.14.1-2
affected

References

github.com/...p/hdf5/security/advisories/GHSA-w7v2-9cmr-pwwj exploit

github.com/...p/hdf5/security/advisories/GHSA-w7v2-9cmr-pwwj

cve.org (CVE-2026-34734)

nvd.nist.gov (CVE-2026-34734)

Download JSON