{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/netcdf-c--4.10.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:unidata:netcdf-c:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-86095"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["netcdf-c (\u003c= 4.10.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Unidata"],"content_html":"\u003cp\u003eUnidata netcdf-c versions through 4.10.1 are affected by an out-of-bounds write vulnerability located in the NC4_HDF5_inq_attname function. This vulnerability is triggered when the library copies HDF5 attribute names into a fixed 256-byte buffer without performing necessary length validation. An attacker can exploit this flaw by providing a specially crafted HDF5 file containing an attribute name exceeding the buffer limit. When an application attempts to enumerate attribute names within the malicious file, the buffer overflow occurs. This memory corruption can result in the termination of the host process, potentially leading to denial-of-service conditions or providing a primitives for more complex exploitation depending on the environment where the netcdf-c library is integrated.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in process instability or crashes, impacting any application or research software that utilizes netcdf-c to process HDF5 files. Given that netCDF is widely used in scientific research, climate modeling, and geophysical data analysis, the vulnerability poses a risk to data integrity and availability in environments that process untrusted or externally sourced datasets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions include identifying software dependencies that utilize the netcdf-c library and planning for updates.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit systems to identify applications linked against netcdf-c versions up to 4.10.1.\u003c/li\u003e\n\u003cli\u003ePrioritize the update of all software components relying on netcdf-c to a patched version once released by Unidata.\u003c/li\u003e\n\u003cli\u003eImplement file-scanning and validation logic for HDF5 files received from untrusted sources to ensure they adhere to expected format specifications before processing by netcdf-c.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T23:28:20Z","date_published":"2026-09-04T23:28:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86095/","summary":"Unidata netcdf-c through version 4.10.1 contains an out-of-bounds write vulnerability in the NC4_HDF5_inq_attname function that can lead to memory corruption and application crashes.","title":"Unidata netcdf-c Out-of-Bounds Write Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86095/"}],"language":"en","title":"CraftedSignal Threat Feed - Netcdf-C (\u003c= 4.10.1)","version":"https://jsonfeed.org/version/1.1"}