A vulnerability was found in HDFGroup HDF5 up to 1.14.1-2 and classified as critical. Affected is the function H5T__ref_mem_setnull of the component h5 File Handler. The manipulation results in heap-based buffer overflow.

This vulnerability is known as CVE-2026-29043. Attacking locally is a requirement. No exploit is available.