CVE-2026-92627
— UNSCOREDPublished 2026-09-16 · Updated 2026-09-18
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution.
Weaknesses
CWE-416
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-0163
- HIGHCVE-2026-11368PoC
- MEDIUMCVE-2026-18785PoC
- MEDIUMCVE-2026-19662
- HIGHCVE-2026-19666
- MEDIUMCVE-2026-50572PoC
- HIGHCVE-2026-56848
- HIGHCVE-2026-71226
Related by shared AI tags and CWE weakness class. Browse the full archive.