PT-2026-26136 · Htslib · Htslib
Daviesrob
·
Publicado
2026-01-01
·
Atualizado
2026-06-05
·
CVE-2026-31962
CVSS v4.0
8.8
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
HTSlib versions prior to 1.23.1
Description
HTSlib is a library used for reading and writing bioinformatics file formats. A heap buffer overflow exists in the
cram decode seq() function when decoding CRAM files. This occurs because the function incorrectly handles records that omit DNA sequence and quality values, leading to a read and write operation beyond the bounds of a heap allocation. Exploitation of this issue, through a crafted CRAM file, could lead to program crashes, data corruption, or potentially arbitrary code execution.Recommendations
Update to HTSlib version 1.23.1 or later.
Exploit
Correção
Improper Validation of Array Index
Out of bounds Read
Memory Corruption
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Htslib