CVE-2019-10269: Buffer Overflow
Published Mar 29, 2019
·Updated
BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bnsrestore function in bntseq.c via a long sequence name in a .alt file.
Affected Software
4 affected componentsFixes available
Burrow-wheeler Aligner Project Burrow-wheeler Aligner<2019-01-23
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
debian/bwa
0.7.17-60.7.17-70.7.18-10.7.19-1
Remediation
Patch Available
Event History
Mar 29, 2019
CVE Published
via MITRE·04:54 AM
Data Sourced
via MITRE·04:54 AM
Description
Data Sourced
via NVD·05:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:12 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·10:01 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:01 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-10269?
CVE-2019-10269 is classified as a critical vulnerability due to the potential for exploitation via stack-based buffer overflow.
2
How do I fix CVE-2019-10269?
To fix CVE-2019-10269, update to a version of BWA later than 2019-01-23.
3
What software versions are affected by CVE-2019-10269?
CVE-2019-10269 affects versions of BWA prior to 2019-01-23.
4
Which platforms are impacted by CVE-2019-10269?
CVE-2019-10269 impacts BWA on Debian and Ubuntu environments.
5
What is the nature of the vulnerability in CVE-2019-10269?
CVE-2019-10269 involves a stack-based buffer overflow in the bns_restore function due to long sequence names in .alt files.