Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-58494

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

A flaw was found in Wasmtime, a runtime for WebAssembly. A WebAssembly System Interface (WASI) guest with a read-only source file capability can exploit this vulnerability. During hard-link creation and renaming operations, the system checks directory permissions but fails to match file permissions on source and destination preopens. This allows the guest to overwrite host files exposed with read permissions through WASI filesystem interfaces.

Отчет

This Moderate-impact flaw in Wasmtime allows a malicious WebAssembly System Interface (WASI) guest to overwrite host files. By exploiting insufficient permission checks during hard-link and rename operations, a guest with read-only file capabilities can modify host files that are exposed with read permissions through WASI filesystem interfaces. This could lead to data integrity issues on the host system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Connectivity Link 1rhcl-1/wasm-shim-rhel9Fix deferred
Red Hat Enterprise Linux 10virt-firmware-rsFix deferred
Red Hat Hardened ImagesrustAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-280
https://bugzilla.redhat.com/show_bug.cgi?id=2498250wasmtime: Wasmtime: Overwrite host files via insufficient permission checks in wasmtime-wasi

EPSS

Процентиль: 2%
0.00119
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
26 дней назад

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

CVSS3: 6.5
nvd
26 дней назад

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.

CVSS3: 6.5
debian
26 дней назад

Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0 ...

EPSS

Процентиль: 2%
0.00119
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-58494