Home

Description

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution.

PUBLISHED Reserved 2026-04-10 | Published 2026-04-10 | Updated 2026-05-20 | Assigner certcc

Problem types

CWE-416: Use After Free

Product status

nasm-3.02rc5
affected

References

github.com/netwide-assembler/nasm/issues/222

sekai.team/blog/nasm-cve-disclosure/cve-2026-6068

cve.org (CVE-2026-6068)

nvd.nist.gov (CVE-2026-6068)

Download JSON