CVE detail
CVE-2020-24978 — CVE-2020-24978
Published 2020-09-04 · Modified 2026-06-17 · Vendor nasm · Product netwide_assembler · Source nvd
CRITICAL
severity
CVSS-derived band
0.0136
EPSS probability
exploitation probability, 30d
69.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References