Skip to content
Fedora 42 Samtools Critical Heap Overflow Denial of Service 2026

Fedora 42 Samtools Critical Heap Overflow Denial of Service 2026

Linuxsecurity •LinuxSecurity Advisories • March 28, 2026

SAM (Sequence Alignment/Map) is a flexible generic format for storing nucleotide sequence alignment. SAM Tools provide various utilities for manipulating alignments in the SAM format, including sorting, merging, indexing and generating alignments in a per-position format. Update Information : Update to 1.23.1

SAM (Sequence Alignment/Map) is a flexible generic format for storing

nucleotide sequence alignment.

SAM Tools provide various utilities for manipulating alignments in the

SAM format, including sorting, merging, indexing and generating

alignments in a per-position format.

* Thu Mar 19 2026 Rasmus Ory Nielsen - 1.23.1-1 - Updated to 1.23.1 * Thu Jan 22 2026 Rasmus Ory Nielsen - 1.23-1 - Updated to 1.23 * Sat Jan 17 2026 Fedora Release Engineering - 1.15.1-9 - Rebuilt for * Mon Jan 5 2026 Marcin Juszkiewicz - 1.15.1-8 - Extend check to handle RISC-V 64-bit architecture port. * Fri Jul 25 2025 Fedora Release Engineering - 1.15.1-7 - Rebuilt for

* Thu Mar 19 2026 Rasmus Ory Nielsen - 1.23.1-1 - Updated to 1.23.1 * Thu Jan 22 2026 Rasmus Ory Nielsen - 1.23-1 - Updated to 1.23 * Sat Jan 17 2026 Fedora Release Engineering - 1.15.1-9 - Rebuilt for * Mon Jan 5 2026 Marcin Juszkiewicz - 1.15.1-8 - Extend check to handle RISC-V 64-bit architecture port. * Fri Jul 25 2025 Fedora Release Engineering - 1.15.1-7 - Rebuilt for

[ 1 ] Bug #2448750 - CVE-2026-31962 htslib: htslib: Heap buffer overflow leading to arbitrary code execution via crafted CRAM file [ 2 ] Bug #2448751 - CVE-2026-31965 htslib: HTSlib: Information disclosure or denial of service via out-of-bounds read in CRAM record processing [ 3 ] Bug #2448755 - CVE-2026-31963 htslib: HTSlib: Arbitrary code execution via crafted CRAM file [ 4 ] Bug #2448756 - CVE-2026-31964 htslib: HTSlib: Denial of Service via NULL pointer dereference in CRAM decoding

[ 1 ] Bug #2448750 - CVE-2026-31962 htslib: htslib: Heap buffer overflow leading to arbitrary code execution via crafted CRAM file [ 2 ] Bug #2448751 - CVE-2026-31965 htslib: HTSlib: Information disclosure or denial of service via out-of-bounds read in CRAM record processing [ 3 ] Bug #2448755 - CVE-2026-31963 htslib: HTSlib: Arbitrary code execution via crafted CRAM file [ 4 ] Bug #2448756 - CVE-2026-31964 htslib: HTSlib: Denial of Service via NULL pointer dereference in CRAM decoding

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1fc0d39acd' at the command line. For more information, refer to the dnf documentation available at

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-1fc0d39acd' at the command line. For more information, refer to the dnf documentation available at