getToken in libr/asm/p/asmx86nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19842.json"