Wasmtime vulnerable to panic when using a dropped extenref-typed element segment
Vulnerability Description
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-30266
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-75hq-h6g9-h4q5
- https://github.com/bytecodealliance/wasmtime/issues/8281
- https://github.com/bytecodealliance/wasmtime/pull/8018
- https://github.com/bytecodealliance/wasmtime/pull/8283
- https://github.com/bytecodealliance/wasmtime/commit/7f57d0bb0948fa56cc950278d0db230ed10e8664
More from bytecodealliance
View All →Affected Vendor
bytecodealliance
View all reports →