CVE-2018-8881: High severity nasm Netwide Assembler vulnerability
Last updated 25 August 2025
Other sources
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Frequently Asked Questions
What is CVE-2018-8881?
CVE-2018-8881 is a vulnerability in Netwide Assembler (NASM) 2.13.02rc2 that allows for a heap-based buffer over-read.
How severe is CVE-2018-8881?
CVE-2018-8881 has a severity score of 7.3 (High).
Which software versions are affected by CVE-2018-8881?
The affected software versions include NASM 2.13.02rc2, as well as specific versions of the Debian and Ubuntu packages.
How can I fix CVE-2018-8881?
To fix CVE-2018-8881, update your NASM software to version 2.14-1, 2.15.05-1, or 2.16.01-1, depending on your distribution.
Where can I find more information about CVE-2018-8881?
You can find more information about CVE-2018-8881 in the references provided: Bugzilla, Ubuntu Security Notice, and OpenSUSE security announcement.