PT-2026-26141 · Htslib · Htslib

Aviesrob

·

Publicado

2026-01-01

·

Atualizado

2026-03-18

·

CVE-2026-31965

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions HTSlib versions 1.21.1 through 1.23.1
Description HTSlib is a library used for reading and writing bioinformatics file formats, specifically CRAM, a compressed format for DNA sequence alignment data. A flaw exists in the cram decode slice() function during CRAM record processing, where validation of the reference ID field occurs too late. This allows for two out-of-bounds read operations to potentially occur before the invalid data is detected. While the function reports an error, the leakage of two values to the caller may present an exploitation opportunity, or the program could crash due to invalid memory access.
Recommendations HTSlib version 1.23.1 includes a fix for this issue. HTSlib version 1.22.2 includes a fix for this issue. HTSlib version 1.21.1 includes a fix for this issue.

Exploit

Correção

Improper Validation of Array Index

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31965
GHSA-MQM2-V645-3QHR

Produtos afetados

Htslib