CVE-2020-24978
Linux Debian vulnerability analysis and mitigation

Overview

A double-free vulnerability was discovered in NASM (Netwide Assembler) version 2.15.04rc3, specifically in the pp_tokline function within asm/preproc.c. The vulnerability was identified and reported on August 3, 2020, and subsequently fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7 (NIST NVD, NASM Bugzilla).

Technical details

The vulnerability exists in the preprocessor component of NASM, specifically in the pp_tokline function at line 6750 of asm/preproc.c. When processing certain input files, the function attempts to free the same memory region twice, triggering a double-free condition. The issue has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NIST NVD).

Impact

The double-free vulnerability could lead to memory corruption, potentially allowing attackers to cause a denial of service condition or possibly achieve arbitrary code execution. The high CVSS score indicates that the vulnerability can be exploited remotely without requiring privileges or user interaction (NIST NVD).

Exploitability

The vulnerability can be triggered by processing specially crafted assembly files using the command nasm -f win -o tmp.o $PoC. A proof-of-concept exploit was provided in the original bug report (NASM Bugzilla).

Mitigation and workarounds

The vulnerability was fixed in NASM through commit 8806c3ca007b84accac21dd88b900fb03614ceb7. Users are advised to upgrade to a version of NASM that includes this fix. The issue affects version 2.15.04rc3 and was addressed in subsequent releases (NIST NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91990HIGH8.7
  • Linux Debian logoLinux Debian
  • python3-tornado
NoNoSep 15, 2026
CVE-2026-91992HIGH8.2
  • Linux Debian logoLinux Debian
  • python-tornado
NoNoSep 15, 2026
CVE-2026-91991MEDIUM6.3
  • Linux Debian logoLinux Debian
  • python-tornado
NoNoSep 15, 2026
CVE-2026-91986MEDIUM5.3
  • Linux Debian logoLinux Debian
  • rust-toolset:rhel8::rust-analyzer
NoNoSep 15, 2026
CVE-2026-48785MEDIUM4.8
  • Linux Debian logoLinux Debian
  • apptainer-sle15_7
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management