---
id: CVE-2026-106547
title: >-
  A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before
  2.2.0 lets a remote attacker cause an application crash and possibly execute
  arbitrary code with a crafted HDF5 file
summary: >-
  A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before
  2.2.0 lets a remote attacker cause an application crash and possibly execute
  arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks
  are …
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-122
vendor: The HDF Group
product: HDF5
affected:
  - HDF5 >= 1.10.0 < 2.2.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:18.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106547'
references:
  - url: 'https://github.com/HDFGroup/hdf5/pull/6529'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-06T21:20:28.986Z'
---

## Overview

A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are read, H5D__fill_init() fills the fill-value buffer from datatype and dataspace metadata in the file. If that metadata is inconsistent with the buffer's allocated size, the write goes past the end of the buffer. The attacker can control the content written through the fill value stored in the file.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
