USN-8248-2
Dashboard / Vulnerabilities / USN-8248-2
USN-8248-2
Summary: nasm regression
Details: USN-8248-1 fixed vulnerabilities in NASM. Unfortunately the update introduced a regression which could cause NASM to crash. This update fixes the problem by reverting the fix for CVE-2021-33450 and CVE-2021-33452 in Ubuntu 24.04 LTS. We apologize for the inconvenience. Original advisory details: Daisy Chen discovered that NASM was vulnerable to a heap buffer overflow when handling certain input. An attacker could possibly use this issue to cause NASM to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-31722) It was discovered that NASM incorrectly handled memory allocation. An attacker could possibly use this issue to cause NASM to use excessive resources, leading to a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2021-33452, CVE-2021-33450)
References: https://ubuntu.com/security/notices/USN-8248-2, https://ubuntu.com/security/CVE-2021-33450, https://ubuntu.com/security/CVE-2021-33452, https://launchpad.net/bugs/2151861
Affected packages
Package
Name: nasm
Purl: pkg:deb/ubuntu/[email protected]~esm2?arch=source&distro=esm-apps/noble
Affected ranges
Type: ECOSYSTEM
Events:
