malicious_cdf5_attr.nc — Malicious CDF-5 file (72 bytes) with gatt_count = 0x2000000000000001
harness.c — Self-contained C harness that creates the malicious file and triggers the crash
Vulnerability
Integer overflow in v1hpg.c:894 — malloc(ncap->nelems * sizeof(NC_attr *)) has no overflow check (dimensions and variables DO have this check). The multiplication… See the full description on the dataset page: https://huggingface.co/datasets/Talson/netcdf-cdf5-attr-overflow-poc.