CVE-2026-6069
DOCUMENTATION: A flaw was found in NASM. The disasm() function contains a stack-based buffer overflow, a memory corruption vulnerability. A remote attacker can exploit this by providing specially crafted input, leading to an out-of-bounds write when the slen value exceeds the buffer capacity during disassembly output formatting. This can result in arbitrary code execution.
STATEMENT: This IMPORTANT flaw in NASM's disasm() function allows arbitrary code execution through a stack-based buffer overflow when processing specially crafted input. Red Hat products are generally not affected by this vulnerability in their default configurations, as NASM is primarily a development tool and not typically exposed to untrusted external input in production environments. Exploitation would require an attacker to provide malicious input to a system actively using NASM for disassembly.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/security/cve/CVE-2026-6069
