CVE-2026-6067: Nasm Netwide Assembler

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and arbitrary code execution.

Affected products

  • Nasm Netwide Assembler: version 3.02 only

Published 2026-04-10. Last modified 2026-06-17.