CVE-2022-46456: Buffer Overflow
Published Jan 4, 2023
·Updated
NASM v2.16 was discovered to contain a global buffer overflow in the component dbgdbgtypevalue at /output/outdbg.c.
Affected Software
15 affected componentsFixes available
nasm Netwide Assembler=2.16
nasm Netwide Assembler=2.16-rc10
nasm Netwide Assembler=2.16-rc11
nasm Netwide Assembler=2.16-rc12
nasm Netwide Assembler=2.16-rc4
nasm Netwide Assembler=2.16-rc5
nasm Netwide Assembler=2.16-rc6
nasm Netwide Assembler=2.16-rc7
nasm Netwide Assembler=2.16-rc8
nasm Netwide Assembler=2.16-rc9
nasm Netwide Assembler=2.16.01
Microsoft cbl2 nasm 2.16-1
Microsoft cm1 nasm 2.16-1
Microsoft azl3 nasm 2.16.01-1
Microsoft azl3 nasm 2.16.01-2
Event History
Jan 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 4, 2025
Data Sourced
via Microsoft·02:55 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:55 AM
Affected Software
Updated
via Microsoft·02:55 AM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-46456?
CVE-2022-46456 is a global buffer overflow vulnerability discovered in NASM v2.16.
2
What component in NASM v2.16 is affected by CVE-2022-46456?
The component dbgdbg_typevalue at /output/outdbg.c is affected by CVE-2022-46456.
3
What is the severity of CVE-2022-46456?
CVE-2022-46456 has a severity rating of medium with a CVSS score of 6.1.
4
How can I fix CVE-2022-46456?
To mitigate CVE-2022-46456, update to the latest version of NASM that includes the fix for this vulnerability, which is version 2.16.01 or higher.
5
Where can I find more information about CVE-2022-46456?
You can find more information about CVE-2022-46456 at the following reference: https://bugzilla.nasm.us/show_bug.cgi?id=3392814