CVE-2023-23108: Crasm Project Crasm

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In crasm 1.8-3, invalid input validation, specific files passed to the command line application, can lead to a NULL pointer dereference in the function Xasc.

Affected products

Published 2023-02-27. Last modified 2026-06-17.