CRITICAL 9.8 Microsoft

CVE-2020-24978

In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.

Microsoft Security Update 2020-Sep: In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.

Affected Products

References

Published: 2020-09-08 · Source: Microsoft · Feed updated: 2026-08-21
This critical severity vulnerability with a CVSS score of 9.8 was published on 2020-09-08 via Microsoft. Affected: azl3 tensorflow 2.16.1-9 on Azure Linux 3.0, cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0.

Risk Timeline

CVE Disclosed2020-09-08 · 2172 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-27211Cloud Hypervisor: Host File Exfiltration via QCOW Backing File AbuseCRITICAL10.0
CVE-2026-64562KVM: nVMX: Hide shadow VMCS right after VMCLEARCRITICAL9.8
CVE-2026-64564sctp: don't free the ASCONF's own transport in DEL-IP processingCRITICAL9.8
CVE-2026-64565Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()CRITICAL9.8
CVE-2026-64593btrfs: do not trim a device which is not writeableCRITICAL9.8
CVE-2026-68121pppoe: reload header pointer after dev_hard_header()CRITICAL9.8
vulnfeed aggregates 9909 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.