---
id: CVE-2026-19028
title: "H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 prior to\_2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allow…"
summary: "H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 prior to\_2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allow…"
severity: medium
cvss: 6.8
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-125
  - CWE-190
  - CWE-1284
vendor: The HDF Group
product: HDF5
affected:
  - HDF5 <=2.3.0
published: '2026-08-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:20.267'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19028'
references:
  - url: 'https://github.com/HDFGroup/hdf5/issues/6488'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/issues/6490'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/pull/6497'
    label: 0253b833-3e77-4dfe-9d57-17db1a2f0a74
  - url: 'https://github.com/HDFGroup/hdf5/issues/6488'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-06T14:24:48.048981Z'
cvssSource: cna
epss: 0.0018
epssPercentile: 0.06959
ingestedAt: '2026-10-06T21:20:28.947Z'
---

## Overview

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 prior to 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
