High severity7.8NVD Advisory· Published Nov 12, 2018· Updated Jun 17, 2026
CVE-2018-19214
CVE-2018-19214
Description
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:a:nasm:netwide_assembler:12.14:rc15:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
- Range: = 2.14rc15
- osv-coords4 versionspkg:rpm/opensuse/nasm&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/nasm&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/nasm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1pkg:rpm/suse/nasm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2
< 2.14.02-lp151.3.3.1+ 3 more
- (no CPE)range: < 2.14.02-lp151.3.3.1
- (no CPE)range: < 2.14.02-lp152.4.3.1
- (no CPE)range: < 2.14.02-3.4.1
- (no CPE)range: < 2.14.02-3.4.1
Patches
Vulnerability mechanics
References
4- repo.or.cz/nasm.git/commit/661f723d39e03ca6eb05d7376a43ca33db478354nvdPatchThird Party Advisory
- bugzilla.nasm.us/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.htmlnvd
News mentions
0No linked articles in our index yet.