Skip to main content

Security update for nasm

0
Low
Published: 07/13/2026 (07/13/2026, 19:29:42 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for nasm fixes the following issues - CVE-2026-6067: heap buffer overflow vulnerability due to a lack of bounds checking in the obj_directive() function (bsc#1261986). - CVE-2026-6068: heap use after free vulnerability in response file processing (bsc#1261985). Changes for nasm: - Update to 3.02: * Fix build problems on C23 compilers using a pre-C23 version of <stdbool.h> which defines bool as a macro in violation of the C23 specification. * The immediate form of the JMPE instruction (opcode 0F B8) has been changed to an absolute address, as in the Itanium Architecture Software Developer's Manual, version 2.3, Volume 4, page 4:249. Hopefully this won't break whatever virtual environments use JMPE, but it is the closest thing there is to an official specification for this opcode. * Being an absolute address, treat it equivalent to a FAR jump and do not default to 64 bits in 64-bit mode. * That JMPE has apparently been wrong all these years is probably as good of a hint as any how much it has been actually used, but it does have the possibility of breaking virtual environments. In that case, please file a bug report to https://bugs.nasm.us with details about the virtual environment, and we will figure out a suitable solution. * Various build fixes. Fix the documentation not building on MacOS because of the cp utility lacking -u there. Also fix not building generally due to wrong link formatting. Another fix was a typo in compiler.h related to a C++ check. * Corrections to assembling encodings: + Fix CMP allowing LOCK which is illegal. + Correct multiple AVX512 instructions such as VCVTSD2SI, VCVTSD2USI, VCVTSS2SI, VCVTSS2USI, VCVTTSD2SI, VCVTTSD2USI, VCVTTSS2SI, VCVTTSS2USI, VGETEXPSH, VGETMANTSH, MOVDDUP, VMOVDDUP. + Fixed other encodings or instruction formats for instructions UWRMSR, CMPSD, VCMPSS, V4FMADDSS, V4FNMADDSS, VCVTDQ2PH, VCVTPD2PH, VCVTPH2UDQ, VCVTQQ2PH, VCVTUDQ2PH, VCVTUQQ2PH, VGETEXPSH, VGETMANTSH, VRCPPH, VRSQRTPH, VCVTPH2BF8, VCVTPH2BF8S, VCVTPH2HF8, VCVTPH2HF8S. + Fixed typos in VP4DPWSSD mnemonic. + Fixed BYTE and WORD operands getting the same encoding on arithmetic instructions such as CMP. + Fixed PUSH not assembling when used with a DWORD in 64-bit mode. This is not a recommended syntax as the operand size is still 64 bits, but was permitted by earlier versions of NASM. + Fix parsing of $--escaped symbols in directives (GLOBAL, STATIC, EXTERN, REQUIRED, COMMON). * Corrections to disassembling: + Shift instructions with the unity operand were getting disassembled to a zero operand instead of one. + JMP, CALL and JMPE disassembled incorrectly with the register operands. * Whole bunch of minor fixes to operand sizes, operand size prefixes. Changes mostly return the behavior known from 2.16.03. * MOV [mem], label would be accepted without size specifiers which could cause unintended consequences. Raise an error if no size was specified and one of the operands is a memory reference and another operands is a label. * JMP NEAR is now the same as JMP STRICT NEAR as the STRICT is redundant here. JMP WORD on the other hand is up for optimization as NEAR and WORD relate to different things -- jump lengths and operation sizes respectively. * Using redundant (or not) but valid operands size prefixes was fixed on instructions such as IRET, PUSHF, POPF, PUSH and POP. * Using an operand size prefix on a JMP or CALL instruction could generate an invalid instruction. This appears to have been a long-standing bug. Specifying the operand size by specifying the size of the immediate explicitly (e.g. JMP DWORD label) has always worked correctly, however. * Add support for C2y-style \o escape sequences, braced escape sequences, and as NASM extensions, decimal escape sequences (\d) and control-character escape sequences (\^). See section 3.4.2. * Fix generation of the short opcodes for ADD, OR, ADC, SBB, AND, SUB, XOR, and CMP AL,imm8. * Fix truncation of the generated constant to 63 bits when invoking a single-line macro when an argument is defined as =/b or =/ub. * Add an %env() preprocessor function as a more robust and flexible alternative to the %! construct. See section 5.5.7. * The maximum number of multi-line macro parameters is now a configurable limit. See section 2.1.32. * The --limit- options and %pragma limit now accept the keywords default, maximum, and reset. See section 2.1.32. * Fix parsing of seg:offs--style FAR pointers in EQU. * Fix the %clear preprocessor directive hanging when given parameters. * The never properly implemented (or documented) preprocessor directives %rmacro and %irmacro are now properly disabled; to avoid breaking existing code, they fall back to %macro and %imacro with a suitable warning. Programmers should not rely on this behavior: in the future, these directives might actually be (properly) implemented. * New listing option -Lc to include the contents of INCBIN files, see secti

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
SUSE Product Security Team
Advisory Id
openSUSE-SU-2026:21333-1
Cve Count
2
Additional Cves
["CVE-2026-6068"]

Threat ID: 6aab496c55bf5e2cf5990d21

Added to database: 09/17/2026, 01:59:08 UTC

Last updated: 09/17/2026, 01:59:08 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses