VulnerabilityAnalyzed
CVE-2025-8842
A vulnerability has been found in NASM Netwide Assember 2.17rc0.
LOW 1.9EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
- CVSS 4.0
- 1.9 LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.23% probability · 13th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-416
- Affected
- nasm/netwide assembler
- Source
- cna@vuldb.com
References
- https://bugzilla.nasm.us/show_bug.cgi?id=3392933Exploit, Issue Tracking, Vendor Advisory
- https://drive.google.com/file/d/11vEV1vMHXO4BrDGhvWAMm0Qo1woiUwVV/view?usp=drive_linkExploit
- https://vuldb.com/?ctiid.319376Permissions Required, VDB Entry
- https://vuldb.com/?id.319376Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.623184Exploit, Third Party Advisory, VDB Entry
- https://bugzilla.nasm.us/show_bug.cgi?id=3392933Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?submit.623184Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.