JLSEC-2026-1384

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1384.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1384.json
JSON Data
https://api.test.osv.dev/v1/vulns/JLSEC-2026-1384
Upstream
Published
2026-08-24T14:19:02Z
Modified
2026-08-24T14:30:55Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (Source: NVD) CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X (Source: CNA) CVSS Calculator
Summary
[none]
Details

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.

Database specific
{
    "license":  "CC-BY-4.0",
    "sources":  [
        {
            "affected":  {
                "hdfgroup:hdf5":  [
                    "< 2.2.0"
                ]
            },
            "database_specific":  {
                "status":  "Analyzed"
            },
            "html_url":  "https://nvd.nist.gov/vuln/detail/CVE-2026-17572",
            "id":  "CVE-2026-17572",
            "imported":  "2026-08-24T14:03:03.177Z",
            "modified":  "2026-08-18T18:56:24.697Z",
            "published":  "2026-07-27T16:17:04.660Z",
            "url":  "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-17572"
        }
    ]
}
References

Affected packages

Julia / HDF5_jll

Package

Name
HDF5_jll
Purl
pkg:julia/HDF5_jll?uuid=0234f1f7-429e-5d53-9886-15a909be8d59

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1384.json"