
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-92627 is a heap-use-after-free vulnerability in The HDF Group's HDF5 library, specifically in the H5T__conv_f_f() function within src/H5Tconv.c. It affects HDF5 versions before 1.14.2 and is triggered when converting compound datatypes containing floating-point members during a dataset read. The vulnerability was published on September 16, 2026, with a patch advisory issued the same day. It carries a CVSS v4.0 base score of 4.6 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is a use-after-free condition (CWE-416) combined with an expired pointer dereference (CWE-825) in the floating-point type conversion routine H5T__conv_f_f(). During a dataset read operation, a temporary buffer allocated via calloc() is freed and then subsequently read within the same conversion routine, leaving a dangling pointer. An attacker must supply a crafted HDF5 file containing a specially constructed compound datatype; exploitation requires user interaction (e.g., a user or automated process opening the malicious file with an HDF5-consuming application such as h5dump). A technical advisory with further details is available from Pulse Security (GitHub Advisory).
Successful exploitation can cause the affected application to crash (denial of service) and, depending on heap layout and memory allocator behavior, may enable further memory corruption leading to arbitrary code execution in the context of the parsing process. Confidentiality impact is low (partial memory disclosure is possible), integrity impact is none in the base case, and availability is impacted through application crashes. The vulnerability is local in attack vector, meaning the attacker must be able to deliver a malicious HDF5 file to a target system where it will be parsed (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.22% (12th percentile), indicating a low near-term probability of exploitation. No threat actor attribution has been reported.
H5T__conv_f_f() during type conversion.h5dump, a scientific data processing tool, or any application linked against the vulnerable HDF5 library).calloc()-allocated buffer is freed and then accessed, triggering the use-after-free.h5dump or other HDF5-consuming applications; core dumps referencing H5T__conv_f_f() or H5Tconv.c in stack traces..h5 or .hdf5 files in directories processed by automated pipelines or user workstations.dmesg, journalctl) showing heap corruption errors or SIGSEGV/SIGABRT signals from HDF5-linked processes; AddressSanitizer output referencing heap-use-after-free in H5T__conv_f_f().The primary remediation is to upgrade HDF5 to version 1.14.2 or later, which contains the fix for this vulnerability (GitHub Advisory). As a workaround, organizations should avoid opening HDF5 files from untrusted or unverified sources, particularly those containing compound datatypes with floating-point members. Implementing file validation and integrity checks (e.g., cryptographic signatures or checksums) before processing HDF5 files in automated pipelines is also recommended.
Red Hat has tracked this vulnerability via their Bugzilla system (Bug 2535513) and assigned it medium priority and severity, with Product Security DevOps Team involvement (Red Hat Bugzilla). The GitHub Advisory Database published the advisory on September 16, 2026, classifying it as Moderate severity (GitHub Advisory). No significant broader media coverage or notable researcher commentary beyond the Pulse Security advisory has been identified at this time.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."