CVE-2026-92627: 
HDF5 vulnerability analysis and mitigation

Overview

CVE-2026-92627 is a heap-use-after-free vulnerability in The HDF Group's HDF5 library, specifically in the H5T__conv_f_f() function within src/H5Tconv.c. It affects HDF5 versions before 1.14.2 and is triggered when converting compound datatypes containing floating-point members during a dataset read. The vulnerability was published on September 16, 2026, with a patch advisory issued the same day. It carries a CVSS v4.0 base score of 4.6 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is a use-after-free condition (CWE-416) combined with an expired pointer dereference (CWE-825) in the floating-point type conversion routine H5T__conv_f_f(). During a dataset read operation, a temporary buffer allocated via calloc() is freed and then subsequently read within the same conversion routine, leaving a dangling pointer. An attacker must supply a crafted HDF5 file containing a specially constructed compound datatype; exploitation requires user interaction (e.g., a user or automated process opening the malicious file with an HDF5-consuming application such as h5dump). A technical advisory with further details is available from Pulse Security (GitHub Advisory).

Impact

Successful exploitation can cause the affected application to crash (denial of service) and, depending on heap layout and memory allocator behavior, may enable further memory corruption leading to arbitrary code execution in the context of the parsing process. Confidentiality impact is low (partial memory disclosure is possible), integrity impact is none in the base case, and availability is impacted through application crashes. The vulnerability is local in attack vector, meaning the attacker must be able to deliver a malicious HDF5 file to a target system where it will be parsed (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.22% (12th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.

Exploitation steps

  1. Craft a malicious HDF5 file: Using HDF5 library APIs or a hex editor, construct an HDF5 file containing a compound datatype with floating-point members designed to trigger the use-after-free in H5T__conv_f_f() during type conversion.
  2. Deliver the file to the target: Social-engineer a user or automated pipeline into opening the crafted file with an HDF5-consuming application (e.g., h5dump, a scientific data processing tool, or any application linked against the vulnerable HDF5 library).
  3. Trigger parsing: The target application reads the dataset, invoking the compound datatype conversion routine. The temporary calloc()-allocated buffer is freed and then accessed, triggering the use-after-free.
  4. Achieve crash or code execution: Depending on heap layout and allocator behavior, the result ranges from an application crash (denial of service) to potential arbitrary code execution in the context of the parsing process (GitHub Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Process: Unexpected crash or segmentation fault in h5dump or other HDF5-consuming applications; core dumps referencing H5T__conv_f_f() or H5Tconv.c in stack traces.
  • File System: Presence of unusual or externally sourced .h5 or .hdf5 files in directories processed by automated pipelines or user workstations.
  • Logs: Application crash logs or system logs (e.g., dmesg, journalctl) showing heap corruption errors or SIGSEGV/SIGABRT signals from HDF5-linked processes; AddressSanitizer output referencing heap-use-after-free in H5T__conv_f_f().

Mitigation and workarounds

The primary remediation is to upgrade HDF5 to version 1.14.2 or later, which contains the fix for this vulnerability (GitHub Advisory). As a workaround, organizations should avoid opening HDF5 files from untrusted or unverified sources, particularly those containing compound datatypes with floating-point members. Implementing file validation and integrity checks (e.g., cryptographic signatures or checksums) before processing HDF5 files in automated pipelines is also recommended.

Community reactions

Red Hat has tracked this vulnerability via their Bugzilla system (Bug 2535513) and assigned it medium priority and severity, with Product Security DevOps Team involvement (Red Hat Bugzilla). The GitHub Advisory Database published the advisory on September 16, 2026, classifying it as Moderate severity (GitHub Advisory). No significant broader media coverage or notable researcher commentary beyond the Pulse Security advisory has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

hdf5

Affected

sid

hdf5

Affected

trixie

hdf5

Affected

Ubuntu

Unknown

bionic (esm-apps)

hdf5

Unknown

devel

hdf5

Unknown

focal (esm-apps)

hdf5

Unknown

jammy

hdf5

Unknown

jammy (esm-apps)

hdf5

Unknown

noble

hdf5

Unknown

noble (esm-apps)

hdf5

Unknown

resolute

hdf5

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related HDF5 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-106547HIGH8.5
  • HDF5 logoHDF5
  • hdf5
NoYesOct 06, 2026
CVE-2026-19027MEDIUM6.9
  • HDF5 logoHDF5
  • hdf5
NoYesAug 06, 2026
CVE-2026-19029MEDIUM6.8
  • HDF5 logoHDF5
  • cpe:2.3:a:hdfgroup:hdf5
NoYesOct 06, 2026
CVE-2026-19028MEDIUM6.8
  • HDF5 logoHDF5
  • hdf5
NoYesAug 06, 2026
CVE-2026-92627MEDIUM4.6
  • HDF5 logoHDF5
  • hdf5
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management