CVE-2018-8881: Canonical Ubuntu Linux

High severity, CVSS 7.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only
  • Nasm Netwide Assembler: version 2.13.02 only

Published 2018-03-20. Last modified 2026-06-17.