CVE-2018-1000886: Nasm Netwide Assembler

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-overflow caused by triggering endless macro generation, crash the program. This attack appear to be exploitable via a crafted nasm input file.

Affected products

  • Nasm Netwide Assembler: version 2.14.01rc5 only; version 2.15 only

Published 2018-12-20. Last modified 2026-06-17.