Логотип exploitDog
bind:CVE-2022-39393
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39393

Количество 4

Количество 4

ubuntu логотип

CVE-2022-39393

около 3 лет назад

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance. This bug has been patched and users should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include disabling the pooling allocator and disabling the `memory-init-cow`.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-39393

около 3 лет назад

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance. This bug has been patched and users should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include disabling the pooling allocator and disabling the `memory-init-cow`.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-39393

около 3 лет назад

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2. ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-wh6w-3828-g9qf

около 3 лет назад

Wasmtime may have data leakage between instances in the pooling allocator

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-39393

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance. This bug has been patched and users should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include disabling the pooling allocator and disabling the `memory-init-cow`.

CVSS3: 8.6
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-39393

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance. This bug has been patched and users should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include disabling the pooling allocator and disabling the `memory-init-cow`.

CVSS3: 8.6
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-39393

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2. ...

CVSS3: 8.6
0%
Низкий
около 3 лет назад
github логотип
GHSA-wh6w-3828-g9qf

Wasmtime may have data leakage between instances in the pooling allocator

CVSS3: 8.6
0%
Низкий
около 3 лет назад

Уязвимостей на страницу