CVE-2026-86095

NameCVE-2026-86095
DescriptionUnidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption and crashes when applications enumerate attribute names.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
netcdf (PTS)bookworm1:4.9.0-3vulnerable
trixie1:4.9.3-1vulnerable
forky, sid1:4.10.1-1vulnerable
netcdf-parallel (PTS)bookworm1:4.9.0-1vulnerable
trixie1:4.9.3-2vulnerable
forky, sid1:4.10.1-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
netcdfsource(unstable)(unfixed)
netcdf-parallelsource(unstable)(unfixed)

Search for package or bug name: Reporting problems