CVE-2020-21686: Nasm Netwide Assembler

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.

Affected products

  • Nasm Netwide Assembler: before 2.15.04 (fixed in 2.15.04)

Published 2023-08-22. Last modified 2026-06-17.