CVE-2023-52284

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
31/12/2023
Last modified:
08/01/2024

Description

Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bytecodealliance:webassembly_micro_runtime:*:*:*:*:*:*:*:* 1.3.0 (excluding)