{"id":"DEBIAN-CVE-2026-31973","details":"SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in the cram-size command, used to write information about how well CRAM files are compressed, a check to see if the `cram_decode_compression_header()` was missing. If the function returned an error, this could lead to a NULL pointer dereference. Exploiting this bug causes a NULL pointer dereference. Typically this will cause the program to crash. Versions 1.23.1, 1.22.2 and 1.21.1 include fixes for this issue. There is no workaround for this issue.","modified":"2026-09-14T17:03:29.570915887Z","published":"2026-03-18T21:16:26.250Z","upstream":["CVE-2026-31973"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-31973"}],"affected":[{"package":{"name":"samtools","ecosystem":"Debian:12","purl":"pkg:deb/debian/samtools?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.16.1-1","1.17-0+exp1","1.17-1","1.18-1","1.19-1","1.19.2-1","1.20-1","1.20-2","1.20-3","1.21-0+exp1","1.21-1","1.22.1-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-31973.json"}},{"package":{"name":"samtools","ecosystem":"Debian:13","purl":"pkg:deb/debian/samtools?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.21-1","1.22.1-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-31973.json"}},{"package":{"name":"samtools","ecosystem":"Debian:14","purl":"pkg:deb/debian/samtools?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.21-1","1.22.1-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-31973.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}