CVE-2026-6067Disclosure(nasm / netwide_assembler)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nasm netwide_assembler systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling a malicious .asm file, potentially leading to heap memory corruption, denial of service (crash), and arbitrary code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netwide_assembler

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
netwide_assembler

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-11: 1Mentions · 2026-06-07: 1Patch / Workaround · 2026-06-07: 1Technical Details · 2026-04-11: 1Technical Details · 2026-06-07: 104-1106-07
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-111
Disclosure1
2026-06-071
Patch1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6067 A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be … https://www.cve.org/CVERecord?id=CVE-2026-6067

    Post summary

    The text announces a heap buffer overflow vulnerability in NASM (CVE‑2026‑6067) with a brief technical description, but offers no information on exploitation, patches, or PoC.

    00010195
    57.1K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora has issued security updates for libssh2 and NASM to fix a remotely triggerable heap overflow and arbitrary code execution bugs tracked as CVE-2026-7598 and CVE-2026-6067, according to Fedora Release Engineering changelogs. https://threatcluster.io/cluster/critical-vulnerabilities-in-fedora-libssh2-and-nasm-addresse-f9f1afba

    Post summary

    The text announces that Fedora has released patches for CVE‑2026‑7598 and CVE‑2026‑6067, describing them as a heap overflow and arbitrary code execution bug, but provides no evidence of active exploitation or proof‑of‑concept.

    0000088
    317 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnasmnetwide_assembler3.02--

Explore more