{"id":"CVE-2026-31973","summary":"NULL pointer dereference in samtools cram-size","details":"SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in the cram-size command, used to write information about how well CRAM files are compressed, a check to see if the `cram_decode_compression_header()` was missing. If the function returned an error, this could lead to a NULL pointer dereference. Exploiting this bug causes a NULL pointer dereference. Typically this will cause the program to crash. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. There is no workaround for this issue.","aliases":["GHSA-x86f-q6fj-cm43"],"modified":"2026-08-12T15:32:20.262202Z","published":"2026-03-18T20:34:00.846Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31973.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-476"]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/03/18/12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31973.json"},{"type":"ADVISORY","url":"https://github.com/samtools/samtools/security/advisories/GHSA-x86f-q6fj-cm43"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31973"},{"type":"FIX","url":"https://github.com/samtools/samtools/commit/06fc2a219b3d7c94d3f412c09f6d1efd51199f2f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/samtools/samtools","events":[{"introduced":"4959cc981ad9725d3c6007687ca372ffcdaa3c80"},{"last_affected":"063c0ed98dcfe9d64238098c693713cd915d7532"},{"introduced":"da72567097265a61650a081c9f68d4a9f45bd105"},{"fixed":"b74903f69aa69a8435a2b5d66b2a6ca67f381a8e"},{"introduced":"32e616e651459318696b0810248060400618374c"},{"fixed":"06fc2a219b3d7c94d3f412c09f6d1efd51199f2f"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:samtools:samtools:*:*:*:*:*:*:*:*","cpe:2.3:a:samtools:samtools:1.23:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.17"},{"last_affected":"1.21.1"},{"introduced":"1.22"},{"fixed":"1.22.2"},{"introduced":"1.23"},{"last_affected":"1.23"}]}}],"versions":["1.23","= 1.23"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:32:20Z","vanir_signatures":[{"source":"https://github.com/samtools/samtools/commit/06fc2a219b3d7c94d3f412c09f6d1efd51199f2f","target":{"file":"cram_size.c","function":"main_cram_size"},"deprecated":false,"digest":{"function_hash":"254310584608370210697700961491219706261","length":1533},"id":"CVE-2026-31973-02aafcad","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["291437655908264484176112766188196650725","143555089471973266180330542232976457665","209448727847962945100743129922385945709","96300466505532565825557882361735933097","94563996022927879658295969450230716727","26444550539555756114567569354931167799","155800386562255349937703831046304917578","142929857891520982117199820792650036138","144590984420228013412976767293248333477","224494977928779077559110037589693226588","135150568860639148424693251568563722313","134770987951680540905293203195812380586","293878082364052759128026929785283065342","18895997584283124756099286096509285426","178042052634451875503295327640092087137","153584621215615035223707669759738390999","61586457859378006444030453365450089823","244179043536484476703345097763521259816","36014334991835432361695189176187925219","44643424144268969604536948028906623575","137907962610211177212746469110140556300","70640637503054260360970948529678974450","201118397383981537552215139604151758561","87531745572545414972260764437917022482","297430539449623781187316172710649937521","303415437738540148667235882242556534624","44644356958269854849887991339236618913","284323807069134950123685677269524142324","337544489456359786392788139096795197914"],"threshold":0.9},"id":"CVE-2026-31973-26f04ed6","signature_type":"Line","signature_version":"v1","source":"https://github.com/samtools/samtools/commit/06fc2a219b3d7c94d3f412c09f6d1efd51199f2f","target":{"file":"cram_size.c"}},{"signature_version":"v1","source":"https://github.com/samtools/samtools/commit/06fc2a219b3d7c94d3f412c09f6d1efd51199f2f","target":{"file":"cram_size.c","function":"cram_size"},"deprecated":false,"digest":{"function_hash":"208623663330854296480414934067465379395","length":3382},"id":"CVE-2026-31973-2e353134","signature_type":"Function"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31973.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}]}