Intel

AIKIDO-2025-10778

cranelift-codegen is vulnerable to Improper Handling of Exceptional Conditions

Improper Handling of Exceptional ConditionsCVE-2025-62711 Published Nov 10, 2025

21

Low Risk

This Affects:

RUSTcranelift-codegen
0.88.0 - 0.124.2
Fixed in 0.125.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper handling of exceptional conditions in the implementation of component-model host-to-WASM trampolines. A malicious actor can craft a specially designed component and invoke it in a way that exploits the setjmp and longjmp functions in C, potentially causing the host to crash through a segmentation fault or assertion failure.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

cranelift-codegen is vulnerable to Improper Handling of Exceptional Conditions in versions 0.88.0 - 0.124.2.

How to fix this

Upgrade the cranelift-codegen library to the patch version.