CVE-2018-20538: Use After Free
Published Dec 28, 2018
·Updated
There is a use-after-free at asm/preproc.c (function ppgetline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests.
Affected Software
1 affected component
nasm Netwide Assembler=2.14.0-rc16
Event History
Dec 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Sep 3, 2025
Data Sourced
via Microsoft·09:40 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-20538?
CVE-2018-20538 is a vulnerability in Netwide Assembler (NASM) 2.14rc1 that allows an attacker to cause a denial of service through a use-after-free vulnerability in the pp_getline function in asm/preproc.c.
2
What is the severity of CVE-2018-20538?
The severity of CVE-2018-20538 is medium with a CVSS score of 5.5.
3
How does CVE-2018-20538 affect Netwide Assembler (NASM)?
CVE-2018-20538 affects Netwide Assembler (NASM) version 2.14rc16.
4
How can an attacker exploit CVE-2018-20538?
An attacker can exploit CVE-2018-20538 by causing a denial of service during certain finish tests.
5
Is there a fix available for CVE-2018-20538?
Yes, upgrading to a version of Netwide Assembler (NASM) higher than or equal to 2.14.0-rc16 resolves the vulnerability.