CVE-2026-31972General(samtools / samtools)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a known reference. On each output line it writes the reference position, optionally the reference DNA base at that position (obtained from a separate file) and all of the DNA bases that aligned to that position. As the output is ordered by position, reference data that is no longer needed is discarded once it has been printed out. Under certain conditions the data could be discarded too early, leading to an attempt to read from a pointer to freed memory. This bug may allow information about program state to be leaked. It may also cause a program crash through an attempt to access invalid memory. This bug is fixed in versions 1.21.1 and 1.22. There is no workaround for this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • samtools

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
samtools

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-19: 2Technical Details · 2026-03-19: 103-19
Signal classification1 categories
General
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-31972 SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a … https://www.cve.org/CVERecord?id=CVE-2026-31972

    Post summary

    The text merely notes the existence of CVE‑2026‑31972 and links to its CVE record, offering no in‑depth technical details, exploitation evidence, or mitigation information.

    00000147
    56.7K followersView on X
  • Open Source Security mailing list@oss_security
    General

    CVE-2026-31972: samtools <= 1.21 Use-after-free in mpileup leading to an invalid read https://www.openwall.com/lists/oss-security/2026/03/18/11 CVE-2026-31973: samtools <= 1.23 NULL pointer dereference in cram-size https://www.openwall.com/lists/oss-security/2026/03/18/12 SAMtools is a program for manipulating bioinformatics file formats

    Post summary

    The message announces two new samtools vulnerabilities, providing brief technical descriptions and links to discussion threads but lacks any mention of exploits, patches, or active use.

    00000233
    4.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamtoolssamtools---

Explore more