CVE-2025-62711
⚪ Do wiadomości
Błąd w Wasmtime umożliwia zdalne wywołanie awarii hosta przez złośliwy komponent.
CVSS
3.1
EPSS
0.4%
Exploit
none
Vendor
bytecodealliance
Opis źródłowy (NVD)
Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been released and is patched to fix this issue. There are no workarounds.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2025-10-24 22:15:49 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 16:10:00 UTC |
Referencje
- https://github.com/bytecodealliance/wasmtime/commit/192f2fcdadfec9d0cf6b58548a85a7307450cbf5 ([email protected]) [Patch]
- https://github.com/bytecodealliance/wasmtime/pull/11592 ([email protected]) [Patch]
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4h67-722j-5pmc ([email protected]) [Patch, Third Party Advisory]