suse · CVE-2023-29581

Quick triage

Priority: medium Published: 2023-04-13 23:14:55 UTC Updated: 2026-03-05 03:43:50 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-29581 severity moderate: SUSE including 2 source package names (yasm, yasm-devel), 32 product×package rows across 17 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 7, … (17 product lines)): Will Not Fix 32.

Description:

yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.

cvelogic Threat Intelligence