
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19029 is a heap-based buffer over-read vulnerability in the HDF5 library's scale-offset filter decoder (H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c) that allows an attacker to cause a denial of service (application crash) via a crafted HDF5 file. The flaw affects HDF5 through version 2.2.0, where the decoder computes an output size of d_nelmts * size bytes and copies from a compressed chunk without verifying the chunk actually contains that many bytes — both values are derived from attacker-controlled filter parameters in the dataset's filter pipeline message. It was published on October 6, 2026, with a patch submitted the same day. The vulnerability carries a CVSS v4.0 base score of 6.8 (Medium) (GitHub Advisory, Feedly).
The root cause is an out-of-bounds read (CWE-125) in the full-precision branch of H5Z__filter_scaleoffset(). When the stored minimum bits equal the full precision of the datatype, the decoder calculates size_out = d_nelmts * p.size and performs a memcpy starting at a fixed 21-byte parameter header offset into the input chunk, without three critical checks: (1) that the chunk is at least as large as the parameter header, (2) that the multiplication d_nelmts * p.size does not overflow size_t, and (3) that size_out does not exceed the bytes actually available after the header. The fix (PR #6718) adds all three bounds checks before the copy (HDF5 PR #6718). Exploitation requires local file access or the ability to supply a crafted HDF5 file to an application that processes it, with passive user interaction (e.g., a user or automated pipeline opening the file) (GitHub Advisory).
Successful exploitation causes the affected application to crash due to an out-of-bounds memory read, resulting in a denial of service. There is no impact on confidentiality or integrity — the vulnerability is limited to availability of the vulnerable system. Applications in scientific computing, data analysis, and research pipelines that automatically ingest HDF5 files from untrusted sources are most at risk, as a single malformed file can repeatedly crash the processing application (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit available at this time, and no evidence of in-the-wild exploitation has been observed. The PR description notes that a PoC will be published in the cve_hdf5 repository, but it had not been released as of the disclosure date (HDF5 PR #6718). The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires an attacker to supply a crafted HDF5 file and have a victim (or automated process) open it, limiting the attack surface (Feedly).
d_nelmts and p.size to produce a large size_out value that exceeds the actual compressed chunk size.d_nelmts * p.size after the 21-byte parameter header, so the decoder will attempt to read beyond the allocated buffer.H5Z__filter_scaleoffset() on the malicious dataset.memcpy triggers a heap buffer over-read, causing the application to crash (HDF5 PR #6718, GitHub Advisory)..h5 or .hdf5 files in data ingestion directories, particularly files with unusual scale-offset filter parameters in their dataset metadata.H5Z__filter_scaleoffset() or H5Zscaleoffset.c; segmentation fault or heap corruption error messages from HDF5-linked processes.Upgrade HDF5 to version 2.2.1 or later, which includes the bounds checks added in PR #6718 (HDF5 PR #6718). As interim mitigations: validate and restrict HDF5 file ingestion to trusted sources only; implement file integrity checks (e.g., checksums or signatures) before processing; and monitor applications for unexpected crashes when handling HDF5 files. Disabling the scale-offset filter in application-level configurations, where feasible, can also reduce exposure (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."