Intel

AIKIDO-2026-898017

wasmtime is vulnerable to Stack-based Buffer Overflow

Stack-based Buffer OverflowGHSA-32h6-97mm-8q3c Published Yesterday

93

Critical Risk

This Affects:

RUSTwasmtime
39.0.0 - 48.0.3
Fixed in 48.0.4
49.0.0 - 49.0.1
Fixed in 49.0.2
Are you affected? Scan for Free

TL;DR

Wasmtime accepts WebAssembly components whose component model async callback function has an invalid type signature because the bundled wasmparser validator checks only the parameter count and never checks the result type. A malicious guest can use this to make the runtime write up to roughly 16KB of guest chosen data onto the host's native stack during an async lifted export call, overwriting return addresses and redirecting control flow to arbitrary host code or crashing the process, which escapes the sandbox. The fix corrects the callback signature validation so malformed components are rejected before they run.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you run untrusted WebAssembly components that use component model async callback exports.

Background info

wasmtime is vulnerable to Stack-based Buffer Overflow in versions 39.0.0 - 48.0.3 and 49.0.0 - 49.0.1.

How to fix this

Upgrade the wasmtime library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform