CVE-2019-10269

NameCVE-2019-10269
DescriptionBWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs926014

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bwa (PTS)jessie0.7.10-1fixed
stretch0.7.15-2+deb9u1fixed
buster0.7.17-3fixed
bullseye0.7.17-6fixed
bookworm0.7.17-7fixed
sid, trixie0.7.18-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bwasourcewheezy(unfixed)end-of-life
bwasourcejessie(not affected)
bwasourcestretch0.7.15-2+deb9u1
bwasource(unstable)0.7.17-3low926014

Notes

[jessie] - bwa <not-affected> (vulnerable code is not present)
https://github.com/lh3/bwa/pull/232
https://github.com/lh3/bwa/commit/20d0a13092aa4cb73230492b05f9697d5ef0b88e

Search for package or bug name: Reporting problems