wasmtime is vulnerable to Stack-based Buffer Overflow
93
Critical Risk
Wasmtime accepts WebAssembly components whose component model async callback function has an invalid type signature because the bundled wasmparser validator checks only the parameter count and never checks the result type. A malicious guest can use this to make the runtime write up to roughly 16KB of guest chosen data onto the host's native stack during an async lifted export call, overwriting return addresses and redirecting control flow to arbitrary host code or crashing the process, which escapes the sandbox. The fix corrects the callback signature validation so malformed components are rejected before they run.
You are affected if you are using a version that falls within the vulnerable range and you run untrusted WebAssembly components that use component model async callback exports.
wasmtime is vulnerable to Stack-based Buffer Overflow in versions 39.0.0 - 48.0.3 and 49.0.0 - 49.0.1.
Upgrade the wasmtime library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.