CVE-2026-6069: Nasm Netwide Assembler

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity.

Affected products

  • Nasm Netwide Assembler: version 3.02 only

Published 2026-04-10. Last modified 2026-06-17.