Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-352 High 7.8

JLSEC-2026-352

JLSEC Published
Modified
Severity
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Packages
HDF5_jll < 2.0.0+0
Aliases / Upstream
CVE-2026-26200 EUVD-2026-7979

HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.

References