CVE-2020-24978 is a critical double-free vulnerability (CWE-415) affecting NASM 2.15.04rc3, specifically within the pp_tokline function in asm/preproc.c. This flaw carries a CVSS score of 9.8, indicating a severe risk with potential for complete compromise (Confidentiality, Integrity, Availability) via a low-complexity network attack requiring no user interaction. While highly severe, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. The vulnerability has been patched in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.15.04CPE matchmatch criteria | cpe:2.3:a:nasm:netwide_assembler:2.15.04:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.