CVE-2025-8842
7.8
HIGH
CVSS 3.1
EPSS 0.05%
Description
A vulnerability has been found in NASM Netwide Assember 2.17rc0. Affected by this issue is the function do_directive of the file preproc.c. The manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
How to fix CVE-2025-8842
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/nasm—no fix listed
Is CVE-2025-8842 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |