A vulnerability categorized as problematic has been discovered in HDF Group HDF5 up to 2.1.1. This affects the function
H5SM__cache_list_deserialize/H5SM__cache_list_verify_chksum of the component SOHM list-index deserialization. Such manipulation of the argument num_messages leads to buffer overflow.
This vulnerability is listed as CVE-2026-17572. The attack may be performed from remote. There is no available exploit.