CVE-2023-31975
NixOS vulnerability analysis and mitigation

Overview

CVE-2023-31975 is a reported memory leak vulnerability in yasm v1.3.0, specifically in the function yasmintnumcopy at /libyasm/intnum.c. The vulnerability was discovered in March 2023 and involves a leak of two 16-byte objects. However, multiple third parties dispute this as a security vulnerability, considering it a minor bug according to the YASM security policy (YASM Issue, OSS Security).

Technical details

The memory leak occurs in two specific allocations: one in the yasmintnumcopy function and another in yasmintnumcreate_uint function, each leaking 16 bytes. The vulnerability has been assigned a CVSS v3.1 base score of 3.3 (LOW) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L. The leak happens when the program processes input files and occurs just before program termination (NVD).

Impact

The actual impact of this vulnerability is considered minimal to non-existent by security experts. The leak only occurs when the program exits and involves just 32 bytes of memory in total, which is automatically reclaimed by the operating system. Even in a worst-case scenario of running yasm as a service processing untrusted input, the security impact would still be negligible (OSS Security).

Mitigation and workarounds

No specific mitigation is required as the issue is considered a minor bug rather than a security vulnerability. The YASM project has established a SECURITY.md policy that specifically addresses such issues, indicating that they should not be treated as security vulnerabilities (OSS Security).

Community reactions

The security community has largely dismissed this CVE as invalid, with multiple experts arguing that it should be withdrawn. Security professionals have criticized the high initial CVSS score (9.8) as completely inappropriate for this type of issue. There has been significant discussion about how memory leaks on program exit should be handled, with some experts noting that such leaks are common and generally acceptable in many software projects (OSS Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management