buildroot ▾
›
2025.02.x ▾
›
vulnerability
›
CVE-2023-31972
Component Overview
Vulnerability Overview
Name
CVE-2023-31972
Source
NVD (
link
)
Debian (
link
)
Description
yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy.
CWEs
CWE-416
CWE-416
Published Date
May 9, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/yasm/yasm/issues/209
Exploit
https://github.com/yasm/yasm/issues/209
Exploit
Analysis
#
Affected Component
Analysis
yasm
Exploitable
Vulnerability Ratings
#
5.5
CVSSv31
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
yasm
buildroot
master
1.3.0
Exploitable
yasm
yocto
kirkstone
1.3.0+gitX
Not Affected
yasm
yocto
scarthgap
1.3.0+git
Not Affected