
Cloud Vulnerability DB
A community-led vulnerabilities database
A double-free vulnerability was discovered in NASM (Netwide Assembler) version 2.15.04rc3, specifically in the pp_tokline function within asm/preproc.c. The vulnerability was identified and reported on August 3, 2020, and subsequently fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7 (NIST NVD, NASM Bugzilla).
The vulnerability exists in the preprocessor component of NASM, specifically in the pp_tokline function at line 6750 of asm/preproc.c. When processing certain input files, the function attempts to free the same memory region twice, triggering a double-free condition. The issue has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NIST NVD).
The double-free vulnerability could lead to memory corruption, potentially allowing attackers to cause a denial of service condition or possibly achieve arbitrary code execution. The high CVSS score indicates that the vulnerability can be exploited remotely without requiring privileges or user interaction (NIST NVD).
The vulnerability can be triggered by processing specially crafted assembly files using the command nasm -f win -o tmp.o $PoC. A proof-of-concept exploit was provided in the original bug report (NASM Bugzilla).
The vulnerability was fixed in NASM through commit 8806c3ca007b84accac21dd88b900fb03614ceb7. Users are advised to upgrade to a version of NASM that includes this fix. The issue affects version 2.15.04rc3 and was addressed in subsequent releases (NIST NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."