CVE-2019-20352: Nasm Netwide Assembler

High severity, CVSS 7.1. EPSS: 0.8% chance of exploitation in the next 30 days.

In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c.

Affected products

  • Nasm Netwide Assembler: version 2.15 only

Published 2020-01-06. Last modified 2026-06-17.