CVE-2024-30266

wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1.
Configurations

No configuration.

History

21 Nov 2024, 09:11

Type Values Removed Values Added
Summary
  • (es) wasmtime es un tiempo de ejecución para WebAssembly. La versión 19.0.0 de Wasmtime contiene una regresión introducida durante su desarrollo que puede provocar que un módulo WebAssembly invitado cause pánico en el tiempo de ejecución del host. Un módulo WebAssembly válido, cuando se ejecuta en tiempo de ejecución, puede provocar este pánico. Esta vulnerabilidad ha sido parcheada en la versión 19.0.1.
References () https://github.com/bytecodealliance/wasmtime/commit/7f57d0bb0948fa56cc950278d0db230ed10e8664 - () https://github.com/bytecodealliance/wasmtime/commit/7f57d0bb0948fa56cc950278d0db230ed10e8664 -
References () https://github.com/bytecodealliance/wasmtime/issues/8281 - () https://github.com/bytecodealliance/wasmtime/issues/8281 -
References () https://github.com/bytecodealliance/wasmtime/pull/8018 - () https://github.com/bytecodealliance/wasmtime/pull/8018 -
References () https://github.com/bytecodealliance/wasmtime/pull/8283 - () https://github.com/bytecodealliance/wasmtime/pull/8283 -
References () https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-75hq-h6g9-h4q5 - () https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-75hq-h6g9-h4q5 -

04 Apr 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-04 16:15

Updated : 2024-11-21 09:11


NVD link : CVE-2024-30266

Mitre link : CVE-2024-30266

CVE.ORG link : CVE-2024-30266


JSON object : View

Products Affected

No product.

CWE
CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')