๐Ÿ” CVE Alert

CVE-2026-6068

MEDIUM 6.5

CVE-2026-6068

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior.

Vendor nasm
Product nasm
Published Apr 10, 2026
Last Updated Apr 10, 2026
Stay Ahead of the Next One

Get instant alerts for nasm nasm

Be the first to know when new medium vulnerabilities affecting nasm nasm are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

NASM / NASM
nasm-3.02rc5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/netwide-assembler/nasm/issues/222