CVE-2026-92627 PUBLISHED

Heap Use-After-Free in H5T__conv_f_f

Assigner: HDFG
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 4.6

Product Status

Vendor The HDF Group
Product HDF5
Versions Default: unaffected
  • Version < 1.14.2 is affected

Credits

  • Denis Andzakovic reporter

References

Problem Types

  • CWE-416 Use after free CWE