CVE-2025-8844Improper Resource Shutdown or Release in Netwide Assember

Severity
4.8MEDIUMNVD
EPSS
0.0%
top 90.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 11
Latest updateAug 12

Description

A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerability affects the function parse_smacro_template of the file preproc.c. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Packages9 packages

🔴Vulnerability Details

2
GHSA
GHSA-3r2j-2686-wg8h: A vulnerability was determined in NASM Netwide Assember 22025-08-11
OSV
CVE-2025-8844: A vulnerability was determined in NASM Netwide Assember 22025-08-11

📋Vendor Advisories

2
Microsoft
NASM Netwide Assember preproc.c parse_smacro_template null pointer dereference2025-08-12
Debian
CVE-2025-8844: nasm - A vulnerability was determined in NASM Netwide Assember 2.17rc0. This vulnerabil...2025