CVE-2026-31964
Description
A flaw was found in HTSlib, a library for reading and writing bioinformatics file formats. When processing specially crafted CRAM (Compressed Reference-aligned Alignment Map) data, specifically records that omit sequence or quality data using the CONST, XPACK, or XRLE encodings, the library attempts to write to a NULL pointer. This NULL pointer dereference can cause the program to crash, leading to a Denial of Service (DoS).
Statement
This MODERATE NULL pointer dereference in HTSlib's CRAM decoder affects the CONST, XPACK, and XRLE encodings when processing records with omitted data. Exploitation requires local access and user interaction. Impact is limited to availability (crash/DoS) with no confidentiality or integrity impact. Affects htslib and python-pysam in EPEL and Fedora. Fixed in versions 1.23.1, 1.22.2, and 1.21.1.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Crash, Exit, or Restart
NULL pointer dereferences usually result in the failure of the process unless exception handling (on some platforms) is available and implemented. Even when exception handling is being used, it can still be very difficult to return the software to a safe state of operation.
Integrity,Confidentiality
Technical Impact: Execute Unauthorized Code or Commands; Read Memory; Modify Memory
In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.