Skip to content
Fedora 42 htslib Urgent Heap Overflow Vulnerability for Code Execution

Fedora 42 htslib Urgent Heap Overflow Vulnerability for Code Execution

Linuxsecurity •LinuxSecurity Advisories • March 28, 2026

HTSlib is an implementation of a unified C library for accessing common file formats, such as SAM, CRAM and VCF, used for high-throughput sequencing data, and is the core library used by samtools and bcftools. Update Information : Update to 1.23.1

HTSlib is an implementation of a unified C library for accessing common file

formats, such as SAM, CRAM and VCF, used for high-throughput sequencing data,

and is the core library used by samtools and bcftools.

* Thu Mar 19 2026 Rasmus Ory Nielsen - 1.23.1-1 - Updated to 1.23.1 * Thu Jan 22 2026 Rasmus Ory Nielsen - 1.23-1 - Updated to 1.23 - Removed outdated patch * Fri Jan 16 2026 Fedora Release Engineering - 1.15.1-10 - Rebuilt for * Thu Jul 24 2025 Fedora Release Engineering - 1.15.1-9 - Rebuilt for

* Thu Mar 19 2026 Rasmus Ory Nielsen - 1.23.1-1 - Updated to 1.23.1 * Thu Jan 22 2026 Rasmus Ory Nielsen - 1.23-1 - Updated to 1.23 - Removed outdated patch * Fri Jan 16 2026 Fedora Release Engineering - 1.15.1-10 - Rebuilt for * Thu Jul 24 2025 Fedora Release Engineering - 1.15.1-9 - Rebuilt for

[ 1 ] Bug #2448750 - CVE-2026-31962 htslib: htslib: Heap buffer overflow leading to arbitrary code execution via crafted CRAM file [ 2 ] Bug #2448751 - CVE-2026-31965 htslib: HTSlib: Information disclosure or denial of service via out-of-bounds read in CRAM record processing [ 3 ] Bug #2448755 - CVE-2026-31963 htslib: HTSlib: Arbitrary code execution via crafted CRAM file [ 4 ] Bug #2448756 - CVE-2026-31964 htslib: HTSlib: Denial of Service via NULL pointer dereference in CRAM decoding

[ 1 ] Bug #2448750 - CVE-2026-31962 htslib: htslib: Heap buffer overflow leading to arbitrary code execution via crafted CRAM file [ 2 ] Bug #2448751 - CVE-2026-31965 htslib: HTSlib: Information disclosure or denial of service via out-of-bounds read in CRAM record processing [ 3 ] Bug #2448755 - CVE-2026-31963 htslib: HTSlib: Arbitrary code execution via crafted CRAM file [ 4 ] Bug #2448756 - CVE-2026-31964 htslib: HTSlib: Denial of Service via NULL pointer dereference in CRAM decoding

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1fc0d39acd' at the command line. For more information, refer to the dnf documentation available at

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1fc0d39acd' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities