<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:55:56 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-348934</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-348934</link>
      <description>EUVD-2026-348934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-348934</guid>
    </item>
    <item>
      <title>fkie_cve-2026-19025</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-19025</link>
      <description>&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;#39;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;#39;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-19025</guid>
    </item>
    <item>
      <title>GHSA-546v-jw2p-gc8p</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-546v-jw2p-gc8p</link>
      <description>&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;#39;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;#39;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-546v-jw2p-gc8p</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-19025 — HDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset open</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-19025</link>
      <description>msrc_CVE-2026-19025</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-19025</guid>
    </item>
    <item>
      <title>OESA-2026-3872 — hdf5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3872</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: hdf5&lt;/p&gt;
&lt;p&gt;HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A critical vulnerability has been identified in HDF5 up to version 1.14.6. The issue affects the H5FS__sect_find_node function in the H5FSsection.c file, leading to a heap-based buffer overflow. The attack can be launched on the local host. The exploit has been publicly disclosed and may be in use.(CVE-2025-6270)&lt;/p&gt;
&lt;p&gt;A vulnerability, classified as problematic, has been identified in HDF5 1.14.6. This issue affects the H5C__load_entry function in the file /src/H5Centry.c, leading to resource consumption. The attack requires local access. The exploit has been publicly disclosed and may be used.(CVE-2025-6817)&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic was found in HDF5 1.14.6, affecting the H5FS__sect_link_size function in the file src/H5FSsection.c. The manipulation leads to a heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.(CVE-2025-7069)&lt;/p&gt;
&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;amp;a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: hdf5&lt;/p&gt;
&lt;p&gt;HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A critical vulnerability has been identified in HDF5 up to version 1.14.6. The issue affects the H5FS__sect_find_node function in the H5FSsection.c file, leading to a heap-based buffer overflow. The attack can be launched on the local host. The exploit has been publicly disclosed and may be in use.(CVE-2025-6270)&lt;/p&gt;
&lt;p&gt;A vulnerability, classified as problematic, has been identified in HDF5 1.14.6. This issue affects the H5C__load_entry function in the file /src/H5Centry.c, leading to resource consumption. The attack requires local access. The exploit has been publicly disclosed and may be used.(CVE-2025-6817)&lt;/p&gt;
&lt;p&gt;A vulnerability classified as problematic was found in HDF5 1.14.6, affecting the H5FS__sect_link_size function in the file src/H5FSsection.c. The manipulation leads to a heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.(CVE-2025-7069)&lt;/p&gt;
&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;amp;a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3872</guid>
    </item>
    <item>
      <title>RHSA-2026:61630 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:61630</link>
      <description>&lt;p&gt;hdf5: HDF5: Denial of Service via crafted file requiring user interaction hdf5: HDF5 library: Denial of Service via crafted HDF5 file processing hdf5: HDF5: Denial of Service due to malformed chunk data in files hdf5: HDF5: Out-of-bounds read due to corrupted file can lead to denial of service hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file HDF5: HDF5: Memory corruption via crafted HDF5 file&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;hdf5: HDF5: Denial of Service via crafted file requiring user interaction hdf5: HDF5 library: Denial of Service via crafted HDF5 file processing hdf5: HDF5: Denial of Service due to malformed chunk data in files hdf5: HDF5: Out-of-bounds read due to corrupted file can lead to denial of service hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file HDF5: HDF5: Memory corruption via crafted HDF5 file&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:61630</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-19025</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19025</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: hdf5, Ubuntu:Pro:16.04:LTS: hdf5, Ubuntu:Pro:18.04:LTS: hdf5, Ubuntu:Pro:20.04:LTS: hdf5, Ubuntu:22.04:LTS: hdf5, Ubuntu:24.04:LTS: hdf5, Ubuntu:26.04:LTS: hdf5&lt;/p&gt;
&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;#39;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: hdf5, Ubuntu:Pro:16.04:LTS: hdf5, Ubuntu:Pro:18.04:LTS: hdf5, Ubuntu:Pro:20.04:LTS: hdf5, Ubuntu:22.04:LTS: hdf5, Ubuntu:24.04:LTS: hdf5, Ubuntu:26.04:LTS: hdf5&lt;/p&gt;
&lt;p&gt;H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&amp;#39;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19025</guid>
    </item>
  </channel>
</rss>
