Description
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior.
INFO
Published Date :
2026-04-10T13:30:38.420Z
Last Modified :
2026-04-10T14:56:52.908Z
Source :
certcc
AFFECTED PRODUCTS
The following products are affected by CVE-2026-6068 vulnerability.
| Vendors | Products |
|---|---|
| Nasm |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-6068.
| URL | Resource |
|---|---|
| https://github.com/netwide-assembler/nasm/issues/222 |
|
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact