HIGH🇬🇧 English

CVE-2022-39393

CVSS 8.6v3.1pub. 2022-11-10upd. 2025-05-02

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance. This bug has been patched and users should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include disabling the pooling allocator and disabling the `memory-init-cow`.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
  • Bytecodealliance Wasmtime

    APP
    Bytecodealliance
    < 1.0.22.0.0 – 2.0.2 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-34987CRITICAL9.0PL ✓ten sam produkt

Wasmtime (Winch): ucieczka z sandboxa WebAssembly, dostęp do pamięci hosta

CVE-2026-34971CRITICAL9.0PL ✓ten sam produkt

Wasmtime Cranelift: ucieczka z sandbox przez błędną kompilację na aarch64

CVE-2023-26489CRITICAL9.9PL ✓ten sam produkt

Błąd obliczania adresu w Cranelift (x86_64) — zapis/odczyt poza obszarem pamięci WebAssembly

CVE-2022-24791HIGH8.1ten sam produkt

Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnera...

CVE-2026-44216MEDIUM5.9ten sam produkt

Wasmtime to runtime dla WebAssembly. W wersjach od 30.0.0 do 36.0.8, 43.0.2 i 44.0.1 logika alokacji pamięci d...