CVE-2026-34734
published 2026-04-09CVE-2026-34734: HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.19%
9.2th percentile
HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was allocated by H5D__typeinfo_init_phase3 and freed by H5D__typeinfo_term.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hdfgroup | hdf5 | < 1.14.1-2 | 1.14.1-2 |
| hdfgroup | hdf5 | <= 1.14.1-2 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HDFGroup HDF5 up to 1.14.1-2 Memmove Call H5T__conv_struct use after free
vuldb·2026-04-09·CVSS 7.8
CVE-2026-34734 [HIGH] HDFGroup HDF5 up to 1.14.1-2 Memmove Call H5T__conv_struct use after free
A vulnerability classified as critical was found in HDFGroup HDF5 up to 1.14.1-2. Affected by this vulnerability is the function H5T__conv_struct of the component Memmove Call Handler. The manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-34734. The attack must be initiated from a local position. There is no exploit available.
Red Hat
hdf5: h5dump: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file
vendor_redhat·2026-04-09·CVSS 7.8
CVE-2026-34734 [HIGH] CWE-825 hdf5: h5dump: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file
hdf5: h5dump: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file
A flaw was found in the HDF5 software, specifically in the h5dump helper utility. An attacker can exploit this vulnerability by providing a specially crafted HDF5 file, leading to a heap-use-after-free condition. This flaw can result in arbitrary code execution, allowing the attacker to take control of the affected system, or cause a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: hdf5 (Red Hat Enterprise Linux AI (RHEL AI) 3) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34734 hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file [epel-all]
bugzilla·2026-04-09·CVSS 7.8
CVE-2026-34734 [HIGH] CVE-2026-34734 hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file [epel-all]
CVE-2026-34734 hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34734 hdf5: h5dump: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file
bugzilla·2026-04-09·CVSS 7.8
CVE-2026-34734 [HIGH] CVE-2026-34734 hdf5: h5dump: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file
CVE-2026-34734 hdf5: h5dump: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file
HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-free. The freed object is referenced in a memmove call from H5T__conv_struct. The original object was allocated by H5D__typeinfo_init_phase3 and freed by H5D__typeinfo_term.
Bugzilla
CVE-2026-34734 hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file [fedora-all]
bugzilla·2026-04-09·CVSS 7.8
CVE-2026-34734 [HIGH] CVE-2026-34734 hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file [fedora-all]
CVE-2026-34734 hdf5: HDF5 h5dump: Arbitrary code execution via a crafted HDF5 file [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
https://github.com/HDFGroup/hdf5/security/advisories/GHSA-w7v2-9cmr-pwwjhttps://access.redhat.com/security/cve/CVE-2026-34734https://bugzilla.redhat.com/show_bug.cgi?id=2457034https://github.com/HDFGroup/hdf5/security/advisories/GHSA-w7v2-9cmr-pwwjhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34734.json
2026-04-09
Published