NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/netwide-assembler/nasm/issues/222 |
|
History
Fri, 10 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasm
Nasm nasm |
|
| Vendors & Products |
Nasm
Nasm nasm |
Fri, 10 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior. | |
| Title | CVE-2026-6068 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-04-10T13:30:38.420Z
Reserved: 2026-04-10T13:29:25.329Z
Link: CVE-2026-6068
No data.
Status : Received
Published: 2026-04-10T14:16:38.723
Modified: 2026-04-10T14:16:38.723
Link: CVE-2026-6068
No data.
OpenCVE Enrichment
Updated: 2026-04-10T14:40:41Z
Weaknesses
No weakness.