-
-
Notifications
You must be signed in to change notification settings - Fork 18.6k
CVE-2026-6067 #508902
Copy link
Copy link
Open
Labels
1.severity: securityIssues which raise a security issue, or PRs that fix oneIssues which raise a security issue, or PRs that fix one
Metadata
Metadata
Assignees
Labels
1.severity: securityIssues which raise a security issue, or PRs that fix oneIssues which raise a security issue, or PRs that fix one
Fields
Give feedbackNo fields configured for issues without a type.
Description
A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and arbitrary code execution.
References
7.5 HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected packages
nasm(2.16.03@nixos-25.11, 3.01@nixos-unstable)