BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bntseq.c via a long sequence name in a .alt file. Reference: https://security-tracker.debian.org/tracker/CVE-2019-10269 https://github.com/lh3/bwa/pull/232 Upstream commit: https://github.com/lh3/bwa/commit/20d0a13092aa4cb73230492b05f9697d5ef0b88e
Created bwa tracking bugs for this issue: Affects: fedora-all [bug 1695534]
Created bwa tracking bugs for this issue: Affects: epel-all [bug 1695535]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.