{"id":"AZL-92850","summary":"CVE-2026-26199 affecting package hdf5 for versions less than 1.14.6-4","details":"HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.","modified":"2026-09-20T05:33:47Z","published":"2026-07-20T16:16:57Z","upstream":["CVE-2026-26199"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26199"}],"affected":[{"package":{"name":"hdf5","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/hdf5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14.6-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92850.json"}}],"schema_version":"1.9.0"}