
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19028 is a denial-of-service vulnerability in the HDF5 library's Fletcher32 filter implementation, caused by an integer underflow leading to a massively out-of-bounds read. The flaw exists in H5Z__filter_fletcher32 within H5Zfletcher32.c in HDF5 versions through 2.3.0. It was reported on June 28, 2026, and published to the NVD and GitHub Advisory Database on August 6, 2026. It carries a CVSS v4.0 base score of 6.8 (Medium) (Github Advisory, Feedly).
The root cause is an integer underflow (CWE-190) combined with an out-of-bounds read (CWE-125) and improper input validation (CWE-1284). In H5Zfletcher32.c, the read path computes src_nbytes = nbytes - FLETCHER_LEN (where FLETCHER_LEN is 4) without first verifying that nbytes is at least 4 bytes. When a crafted HDF5 file contains a Fletcher32-filtered chunk smaller than 4 bytes, this subtraction underflows the size_t variable to approximately SIZE_MAX - 3 (observed as 18446744073709551612), which is then passed directly to H5_checksum_fletcher32(), triggering a massive out-of-bounds read and SIGSEGV. The vulnerability is reachable from any application using H5Dread() on a chunked dataset with a Fletcher32 filter, including the h5ls and h5dump command-line tools (HDF5 Issue #6488, HDF5 Issue #6490, HDF5 PR #6497).
Successful exploitation causes an application crash (SIGSEGV) in any process that reads a maliciously crafted HDF5 file containing a Fletcher32-filtered chunk smaller than 4 bytes, resulting in a denial of service. The impact is limited to availability — there is no confidentiality or integrity impact identified. Any application or pipeline that processes untrusted HDF5 files using the affected library versions is at risk, including scientific computing workflows, data analysis tools, and HDF5 command-line utilities (Github Advisory, Feedly).
The vulnerability requires local access and passive user interaction (a user or process must open a crafted HDF5 file), and no privileges are required. Proof-of-concept input files (Heap_Corruption.zip and Heap_Corruption_2.zip) were provided in the original bug reports, demonstrating reproducible crashes with h5dump and h5ls -d respectively. The NVD SSVC assessment classifies exploitation as "poc" and not automatable. The EPSS score is approximately 0.127% (3rd percentile), and there is no evidence of in-the-wild exploitation or CISA KEV listing (HDF5 Issue #6488, HDF5 Issue #6490, Github Advisory).
h5dump Heap_Corruption or h5ls -d Heap_Corruption_2, or any application calling H5Dread() on the malformed dataset.H5Z__filter_fletcher32() computes src_nbytes = nbytes - 4 without bounds checking; with nbytes=0, src_nbytes underflows to 18446744073709551612 (SIZE_MAX - 3).H5_checksum_fletcher32(), which attempts to read far beyond the allocated buffer, causing a SIGSEGV and application crash (HDF5 Issue #6488, HDF5 Issue #6490, HDF5 PR #6497).h5dump, h5ls, or any application linked against libhdf5 while reading HDF5 files.H5_checksum_fletcher32 at H5checksum.c:115 with _len=18446744073709551612; stack traces showing the call chain H5Dread → H5D__read → H5D__chunk_read → H5D__chunk_lock → H5Z_pipeline → H5Z__filter_fletcher32 → H5_checksum_fletcher32..h5, .hdf5) in directories processed by automated pipelines; core dump files generated by HDF5-processing applications.Update HDF5 to a version newer than 2.3.0 that includes the fix from pull request #6497, which adds a lower-bound check rejecting nbytes < FLETCHER_LEN before the subtraction in H5Z__filter_fletcher32(). Until patching is possible, avoid opening untrusted or unverified HDF5 files with tools such as h5ls or h5dump, and implement input validation to detect malformed HDF5 files before processing. Organizations running automated HDF5 ingestion pipelines should restrict file sources to trusted origins as an interim control (HDF5 PR #6497, Github Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."