Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6068

Опубликовано: 10 апр. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution.

A flaw was found in NASM, a Netwide Assembler. This vulnerability, known as a heap use after free, occurs when the program attempts to use memory that has already been released. During response file processing, a pointer to freed memory is retained and later accessed. This can lead to data corruption or unexpected program behavior.

Отчет

This Moderate impact vulnerability in NASM affects Red Hat Enterprise Linux and Fedora. A heap use after free flaw occurs during response file processing, which could lead to data corruption or unexpected program behavior when a specially crafted response file is processed. Exploitation requires the processing of a malicious response file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nasmFix deferred
Red Hat Enterprise Linux 6nasmOut of support scope
Red Hat Enterprise Linux 7nasmFix deferred
Red Hat Enterprise Linux 8nasmFix deferred
Red Hat Enterprise Linux 9nasmFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2457290nasm: NASM: Heap use after free vulnerability in response file processing

EPSS

Процентиль: 33%
0.00414
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
4 месяца назад

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution.

CVSS3: 9.6
nvd
4 месяца назад

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution.

CVSS3: 9.6
debian
4 месяца назад

NASM contains a heap use after free vulnerability in response file (-@ ...

CVSS3: 6.5
github
4 месяца назад

NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior.

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость функции process_respfile файла asm/nasm.c ассемблера Netwide Assembler (NASM), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 33%
0.00414
Низкий

6.8 Medium

CVSS3