CVE-2026-6069

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
10/04/2026
Last modified:
16/04/2026

Description

NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nasm:netwide_assembler:3.02:rc5:*:*:*:*:*:*


References to Advisories, Solutions, and Tools