{"id":"AZL-99894","summary":"CVE-2026-86095 affecting package netcdf 4.9.0-4","details":"Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.","modified":"2026-09-12T05:28:09Z","published":"2026-09-04T23:18:03Z","upstream":["CVE-2026-86095"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86095"}],"affected":[{"package":{"name":"netcdf","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/netcdf"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"4.9.0-4"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99894.json"}}],"schema_version":"1.9.0"}