LiveActive security incident?Get immediate response
CVE Record

CVE-2021-33458: An issue was discovered in yasm version 1.3.0.

An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in find_cc() in modules/preprocs/nasm/nasm-pp.c.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

CVE-2021-33458 is a crash bug in Yasm 1.3.0. A NULL pointer dereference in the NASM preprocessor path can make the tool terminate unexpectedly when it handles problematic input. The public sources do not provide a CVSS score, confirmed fix version, or evidence of active exploitation.

Executive priority

Handle through normal vulnerability management unless Yasm processes untrusted files in production or shared build infrastructure. The known impact is a crash, and the sources do not show active exploitation or a confirmed high-impact security outcome.

Technical view

The CVE describes a NULL pointer dereference in find_cc() within modules/preprocs/nasm/nasm-pp.c in Yasm 1.3.0. The practical impact supported by the sources is process crash or denial of service during input processing. No source in the bundle establishes remote code execution, privilege escalation, or exploitation in the wild.

Likely exposure

Exposure is most likely where Yasm 1.3.0 is installed in build pipelines, developer workstations, packaging systems, or services that process untrusted assembly or NASM-style preprocessor input.

Exploitation context

The CVE is not listed as KEV in the provided bundle. Public references include an issue and a gist, but the bundle does not prove active exploitation, weaponized use, or broad targeting. Treat this primarily as an input-triggered crash risk unless vendor evidence says otherwise.

Researcher notes

Evidence is sparse: no CVSS, CWE, CPE, fixed version, or vendor advisory is provided in the bundle. The strongest supported conclusion is denial of service via NULL pointer dereference in Yasm 1.3.0 NASM preprocessing. Avoid overstating impact beyond crash behavior.

Mitigation direction

  • Inventory systems and build images for Yasm 1.3.0.
  • Check Yasm project guidance for fixed releases or maintained alternatives.
  • Avoid processing untrusted assembly or preprocessor input with affected Yasm.
  • Run parsing jobs with least privilege and isolated build workers.
  • Monitor build systems for repeated Yasm crashes or abnormal job failures.

Validation and detection

  • Confirm installed Yasm versions on developer and CI systems.
  • Identify workflows where Yasm processes externally supplied source files.
  • Review CI and build logs for Yasm crashes or segmentation faults.
  • Track the GitHub issue for fix or maintainer guidance.
  • Document whether affected use is isolated, internal-only, or externally influenced.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-33458 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.