LOW🇬🇧 English

CVE-2023-27477

CVSS 3.1v3.1pub. 2023-03-08upd. 2024-11-21

Wasmtime to szybkie i bezpieczne środowisko wykonawcze dla WebAssembly. Backend generacji kodu Wasmtime'a, Cranelift, zawiera błąd na platformach x86_64 dotyczący instrukcji WebAssembly `i8x16.select`, która zwraca nieprawidłowe wyniki, gdy ten sam operand jest dostarczony do instrukcji, a niektóre wybrane indeksy są większe niż 16. Błąd przesunięcia o jeden w obliczeniu maski instrukcji `pshufb` powoduje zwrócenie nieprawidłowych wyników, jeśli pola są wybierane z drugiego wektora. Ten błąd został naprawiony w wersjach Wasmtime 6.0.1, 5.0.1 i 4.0.1. Zalecane jest uaktualnienie do tych zaktualizowanych wersji. Jeśli nie możesz teraz uaktualnić, możesz uniknąć tej błędnej kompilacji, wyłączając propozycję Wasm SIMD. Ponadto błąd występuje tylko na hostach x86_64 — inne

Pokaż oryginał (EN)

wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than 16. There is an off-by-one error in the calculation of the mask to the `pshufb` instruction which causes incorrect results to be returned if lanes are selected from the second vector. This codegen bug has been fixed in Wasmtiem 6.0.1, 5.0.1, and 4.0.1. Users are recommended to upgrade to these updated versions. If upgrading is not an option for you at this time, you can avoid this miscompilation by disabling the Wasm simd proposal. Additionally the bug is only present on x86_64 hosts. Other platforms such as AArch64 and s390x are not affected.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
  • Bytecodealliance Cranelift Codegen

    APP
    Bytecodealliance
    0.92.00.93.00.84.0 – 0.91.1 (bez)
  • Bytecodealliance Wasmtime

    APP
    Bytecodealliance
    5.0.06.0.00.37.0 – 4.0.1 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-34987CRITICAL9.0PL ✓ten sam produkt

Wasmtime (Winch): ucieczka z sandboxa WebAssembly, dostęp do pamięci hosta

CVE-2026-34971CRITICAL9.0PL ✓ten sam produkt

Wasmtime Cranelift: ucieczka z sandbox przez błędną kompilację na aarch64

CVE-2023-26489CRITICAL9.9PL ✓ten sam produkt

Błąd obliczania adresu w Cranelift (x86_64) — zapis/odczyt poza obszarem pamięci WebAssembly

CVE-2022-39393HIGH8.6ten sam produkt

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtim...

CVE-2022-24791HIGH8.1ten sam produkt

Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnera...