CVE-2025-8842

MEDIUM

NASM Netwide Assembler 2.17rc0 - Use-After-Free in do_directive Function

Title source: llm
STIX 2.1

Description

A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.319376
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.319376
Exploit, Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.623184
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://bugzilla.nasm.us/show_bug.cgi?id=3392933

Scores

CVSS v3 5.3
EPSS 0.0020
EPSS Percentile 10.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-416
Status published
Products (1)
nasm/netwide_assembler 2.17 rc0
Published Aug 11, 2025
Tracked Since Feb 18, 2026