CVE-2026-31972 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 19, 2026
SAMtools - Use After Free
Overview
SAMtools < 1.21.1 and < 1.22 contain a use-after-free vulnerability in the mpileup command caused by premature discarding of reference data, letting attackers cause information disclosure or program crash, exploit requires crafted input data.
Severity & Score
Impact
Attackers can cause program crashes or leak information about program state, potentially disrupting bioinformatics workflows.
Mitigation
Update to version 1.21.1 or 1.22 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-31972 - Critical (9.8) SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs DNA sequences that have been aligned against a known reference. On each output line it writes the reference position, optionally... š https://www.thehackerwire.com/vulnerability/CVE-2026-31972/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-31972
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- use_after_free
- Status
- confirmed
- EPSS
- 1.5%
- Social Posts
- 1
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H