Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-17572

CVE-2026-17572: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium5.5

    Medium [CVE-2026-17572] Denial of Service via crafted file requiring user interaction

    CVE-2026-17572Source published Source updated

    Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum. A flaw was found in HDF5, a data management library. The malformed file can trigger out-of-bounds memory operations, leading to application crashes or instability. This Moderate impact vulnerability in HDF5 requires user interaction to process a specially crafted HDF5 file, limiting the attack vector to local scenarios. Successful exploitation can lead to a denial of service. The HDF5 library is used in Red…

    Affected products in this advisory
    • Red Hat AI Inference Server
    • Red Hat Enterprise Linux AI (RHEL AI) 3
    • Red Hat OpenShift AI (RHOAI)
    Source-reported affected versions
    • 2.1.1
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery