CVE-2024-30266
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/04/2024
Last modified:
02/09/2025
Description
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1.
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bytecodealliance:wasmtime:19.0.0:*:*:*:*:rust:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/bytecodealliance/wasmtime/commit/7f57d0bb0948fa56cc950278d0db230ed10e8664
- https://github.com/bytecodealliance/wasmtime/issues/8281
- https://github.com/bytecodealliance/wasmtime/pull/8018
- https://github.com/bytecodealliance/wasmtime/pull/8283
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-75hq-h6g9-h4q5
- https://github.com/bytecodealliance/wasmtime/commit/7f57d0bb0948fa56cc950278d0db230ed10e8664
- https://github.com/bytecodealliance/wasmtime/issues/8281
- https://github.com/bytecodealliance/wasmtime/pull/8018
- https://github.com/bytecodealliance/wasmtime/pull/8283
- https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-75hq-h6g9-h4q5



