Skip to main content
Vulnerability Database/CVE-2026-106547

CVE-2026-106547: HDF5 Heap Buffer Overflow Vulnerability

CVE-2026-106547 is a heap-based buffer overflow in HDF5 that allows attackers to crash applications and execute arbitrary code via crafted files. This post explains technical details, affected versions, and mitigation.

Published:

CVE-2026-106547 Overview

CVE-2026-106547 is a heap-based buffer overflow in the H5VM_array_fill() function located in src/H5VM.c within the HDF5 library before version 2.2.0. The flaw triggers when HDF5 reads unallocated chunks of a dataset and H5D__fill_init() populates the fill-value buffer using datatype and dataspace metadata stored in the file. When that metadata is inconsistent with the allocated buffer size, the write operation extends past the buffer boundary. An attacker who supplies a crafted HDF5 file can crash the application or potentially execute arbitrary code. The vulnerability is classified under [CWE-122: Heap-based Buffer Overflow].

Critical Impact

A crafted HDF5 file can corrupt heap memory in any application that uses HDF5 to parse untrusted files, enabling denial of service and potential arbitrary code execution.

Affected Products

  • HDF5 library versions prior to 2.2.0
  • Applications linking against vulnerable HDF5 releases that parse untrusted .h5 files
  • Scientific and data-processing pipelines that ingest third-party HDF5 datasets

Discovery Timeline

  • 2026-10-06 - CVE-2026-106547 published to the National Vulnerability Database
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-106547

Vulnerability Analysis

The defect resides in HDF5's chunked dataset read path. When an application reads a chunk that has not been written to disk, HDF5 must synthesize the chunk content from the dataset's declared fill value. H5D__fill_init() prepares a buffer sized according to one set of metadata, while H5VM_array_fill() performs the write using separate datatype and dataspace fields. When these fields disagree, H5VM_array_fill() copies more bytes than the destination buffer can hold.

Because the fill value is stored inside the HDF5 file itself, an attacker fully controls the bytes written past the buffer boundary. This gives the attacker precise control over adjacent heap contents, which is the primary condition for converting a heap overflow into code execution through techniques such as function pointer overwrite or heap metadata corruption.

Root Cause

The root cause is missing cross-validation between the datatype size, dataspace element count, and the allocated fill-value buffer length. HDF5 trusts file-provided metadata without reconciling it against the buffer size computed during allocation. This design pattern violates safe boundary handling and matches the [CWE-122] weakness class.

Attack Vector

Exploitation requires a user to open a malicious HDF5 file in an application that uses the vulnerable library. The CVSS 4.0 vector indicates a local attack path with user interaction. Delivery vectors include email attachments, shared research datasets, model files distributed through machine learning repositories, and data exchanged between scientific collaborators. No authentication is required against the HDF5 library itself. See the HDF5 Pull Request #6529 for the upstream fix and technical discussion.

// No verified proof-of-concept code is published for CVE-2026-106547.
// Refer to HDF5 Pull Request #6529 for the authoritative patch details.

Detection Methods for CVE-2026-106547

Indicators of Compromise

  • Application crashes, SIGSEGV signals, or heap corruption aborts when opening HDF5 files from untrusted sources
  • HDF5 files containing inconsistent datatype size, dataspace dimensions, and fill-value length fields
  • Unexpected child processes or shell invocations spawned by applications that parse .h5 files

Detection Strategies

  • Scan HDF5 inputs with h5dump or h5check to flag files whose fill-value size does not match the product of datatype size and dataspace element count
  • Deploy AddressSanitizer or Valgrind in test environments to catch heap overflows during HDF5 parsing
  • Alert on crash telemetry from applications known to link HDF5, correlating process name with recently opened file paths

Monitoring Recommendations

  • Collect endpoint telemetry for scientific computing hosts, Jupyter servers, and ML training nodes that process external HDF5 data
  • Monitor file ingestion workflows for .h5, .hdf5, and .he5 files originating outside trusted repositories
  • Forward application crash dumps and process lineage events to a central data lake for retrospective hunting

How to Mitigate CVE-2026-106547

Immediate Actions Required

  • Upgrade HDF5 to version 2.2.0 or later across all systems and container images
  • Rebuild and redeploy applications that statically link HDF5 after upgrading the library
  • Restrict ingestion of HDF5 files to vetted sources until patched versions are deployed

Patch Information

The fix is tracked in HDF5 Pull Request #6529 and is included in HDF5 2.2.0. Operators should pull the updated release from the HDF Group distribution channels, update OS package manager mirrors, and refresh any pinned versions in requirements.txt, conda environments, Dockerfiles, and HPC module files.

Workarounds

  • Avoid opening HDF5 files from untrusted or unauthenticated sources until the library is patched
  • Run HDF5-consuming applications inside sandboxed containers with no network egress and minimal filesystem access
  • Enable compiler-level hardening such as -D_FORTIFY_SOURCE=2, stack canaries, and ASLR for applications that must process external HDF5 data
bash
# Verify installed HDF5 version and upgrade
h5cc -showconfig | grep -i version

# Example upgrade via pip for h5py bundled builds
pip install --upgrade 'h5py>=3.12' 'hdf5>=2.2.0'

# Example upgrade via conda
conda update -c conda-forge hdf5

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.