CVE-2026-6067 PUBLISHED

CVE-2026-6067

Assigner: certcc
Reserved: 10.04.2026 Published: 10.04.2026 Updated: 10.04.2026

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and arbitrary code execution.

Product Status

Vendor NASM
Product NASM
Versions
  • Version nasm-3.02rc5 is affected

References

Problem Types

  • CWE-787: Out-of-bounds Write