PT-2026-26146 · Htslib · Htslib

Harrison Green

·

Publicado

2026-01-01

·

Atualizado

2026-03-19

·

CVE-2026-31970

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions HTSlib versions prior to 1.23.1 HTSlib version 1.22.2 HTSlib version 1.21.1
Description HTSlib is a library used for reading and writing bioinformatics file formats. A heap buffer overflow can occur in the BGZF index file reader due to an integer overflow in the bgzf index load hfile() function. This overflow leads to an undersized buffer allocation, and subsequent writes to this buffer can cause a crash or overwrite heap structures. Exploitation may lead to arbitrary code execution if a user opens a specially crafted file.
Recommendations Versions prior to 1.23.1: Update to version 1.23.1 or later. Version 1.22.2: Update to version 1.23.1 or later. Version 1.21.1: Update to version 1.23.1 or later. Discard any .gzi index files from untrusted sources. Recreate index files using the bgzip -r option.

Exploit

Correção

Integer Overflow

Memory Corruption

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31970
GHSA-P345-84HX-FQ6Q

Produtos afetados

Htslib