Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4v2-cjqp-rfmq

Опубликовано: 08 дек. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.4

Описание

Critical Use-After-Free in Wasmi's Linear Memory

Summary

A use-after-free vulnerability has been discovered in the linear memory implementation of Wasmi. This issue can be triggered by a WebAssembly module under certain memory growth conditions, potentially leading to memory corruption, information disclosure, or code execution.

Impact

  • Confidentiality: High – attacker-controlled memory reads possible.
  • Integrity: High – memory corruption may allow arbitrary writes.
  • Availability: High – interpreter crashes possible.

Affected Versions

Wasmi v0.41.0 through Wasmi v1.0.0.

Workarounds

  • Upgrade to the latest patched version of Wasmi.
  • Consider limiting the maximum linear memory sizes where feasible.

Credits

This vulnerability was discovered by Robert T. Morris (RTM).

Пакеты

Наименование

wasmi

rust
Затронутые версииВерсия исправления

>= 0.41.0, < 0.41.2

0.41.2

Наименование

wasmi

rust
Затронутые версииВерсия исправления

>= 0.42.0, < 0.47.1

0.47.1

Наименование

wasmi

rust
Затронутые версииВерсия исправления

>= 0.50.0, < 0.51.3

0.51.3

Наименование

wasmi

rust
Затронутые версииВерсия исправления

>= 1.0.0, < 1.0.1

1.0.1

EPSS

Процентиль: 4%
0.00017
Низкий

8.4 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 8.4
nvd
около 2 месяцев назад

Wasmi is a WebAssembly interpreter focused on constrained and embedded systems. In versions 0.41.0, 0.41.1, 0.42.0 through 0.47.1, 0.50.0 through 0.51.2 and 1.0.0, Wasmi's linear memory implementation leads to a Use After Free vulnerability, triggered by a WebAssembly module under certain memory growth conditions. This issue potentially leads to memory corruption, information disclosure, or code execution. This issue is fixed in versions 0.41.2, 0.47.1, 0.51.3 and 1.0.1. To workaround this issue, consider limiting the maximum linear memory sizes where feasible.

EPSS

Процентиль: 4%
0.00017
Низкий

8.4 High

CVSS3

Дефекты

CWE-416