CVE-2021-33450
CVE-2021-33450 is a medium-severity vulnerability in Nasm Netwide Assembler with a CVSS 3.x base score of 5.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-401.
Key facts
- Severity: Medium (CVSS 3.x base score 5.5)
- EPSS exploit prediction: 0% (26th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-401
- Affected product: Nasm Netwide Assembler
- Published:
- Last modified:
Description
An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
Frequently asked questions
- What is CVE-2021-33450?
- An issue was discovered in NASM version 2.16rc0. There are memory leaks in nasm_calloc() in nasmlib/alloc.c.
- How severe is CVE-2021-33450?
- CVE-2021-33450 has a CVSS 3.x base score of 5.5, rated medium severity. It is exploitable over local access with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2021-33450 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (26th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-33450?
- CVE-2021-33450 affects Nasm Netwide Assembler. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-33450?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-33450 published?
- CVE-2021-33450 was published on 2022-07-26 and last updated on 2026-06-17.
References
- https://bugzilla.nasm.us/show_bug.cgi?id=3392758
- https://gist.github.com/Clingto/bb632c0c463f4b2c97e4f65f751c5e6d
Affected products (1)
- cpe:2.3:a:nasm:netwide_assembler:2.16:rc0:*:*:*:*:*:*
More vulnerabilities in Nasm Netwide Assembler
- CVE-2004-1287 — Critical (CVSS 10.0): Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via…
- CVE-2020-24978 — Critical (CVSS 9.8): In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit…
- CVE-2026-6068 — Critical (CVSS 9.6): NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed…
- CVE-2008-7177 — Critical (CVSS 9.3): Buffer overflow in the listing module in Netwide Assembler (NASM) before 2.03.01 has unknown impact and attack vectors,…
- CVE-2023-31722 — High (CVSS 7.8): There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891).
- CVE-2022-44370 — High (CVSS 7.8): NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
All CVEs affecting Nasm Netwide Assembler →
Other CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities
- CVE-2026-46289 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in…
- CVE-2025-39948 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The…
- CVE-2025-21954 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently…
- CVE-2024-57947 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map…
- CVE-2024-56779 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent…
- CVE-2024-36911 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo…
Browse all CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities →