Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-15412

Опубликовано: 01 янв. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.

A flaw was found in wabt. A local user can exploit an out-of-bounds read vulnerability by manipulating the wabt::Decompiler::VarName function within the wasm-decompile component. This can lead to information disclosure, denial of service, and potentially arbitrary code execution.

Отчет

This vulnerability is rated Moderate which exists in the wasm-decompile utility of the wabt package and requires local access to exploit. An attacker with local access could provide a specially crafted WebAssembly binary to the wasm-decompile tool, leading to an out-of-bounds read. This issue affects components like wabt in Fedora and firefox, thunderbird in Red Hat Enterprise Linux.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2426694wabt: wabt: Arbitrary code execution, information disclosure, and denial of service via out-of-bounds read

EPSS

Процентиль: 8%
0.00186
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
8 месяцев назад

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.

CVSS3: 5.3
nvd
8 месяцев назад

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.

CVSS3: 5.3
debian
8 месяцев назад

A security vulnerability has been detected in WebAssembly wabt up to 1 ...

CVSS3: 5.3
github
8 месяцев назад

A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.

EPSS

Процентиль: 8%
0.00186
Низкий

7.1 High

CVSS3