PT-2026-26136 · Htslib · Htslib

Daviesrob

·

Publicado

2026-01-01

·

Atualizado

2026-06-05

·

CVE-2026-31962

CVSS v4.0

8.8

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HTSlib versions prior to 1.23.1
Description HTSlib is a library used for reading and writing bioinformatics file formats. A heap buffer overflow exists in the cram decode seq() function when decoding CRAM files. This occurs because the function incorrectly handles records that omit DNA sequence and quality values, leading to a read and write operation beyond the bounds of a heap allocation. Exploitation of this issue, through a crafted CRAM file, could lead to program crashes, data corruption, or potentially arbitrary code execution.
Recommendations Update to HTSlib version 1.23.1 or later.

Exploit

Correção

Improper Validation of Array Index

Out of bounds Read

Memory Corruption

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31962
GHSA-XXMP-V7H3-GPWP
OESA-2026-2547

Produtos afetados

Htslib