GHSA-g4v2-cjqp-rfmq
Critical Use-After-Free in Wasmi's Linear Memory
Details
### Summary
A use-after-free vulnerability has been discovered in the linear memory implementation of Wasmi. This issue can be triggered by a WebAssembly module under certain memory growth conditions, potentially leading to memory corruption, information disclosure, or code execution.
### Impact
- **Confidentiality:** High – attacker-controlled memory reads possible. - **Integrity:** High – memory corruption may allow arbitrary writes. - **Availability:** High – interpreter crashes possible.
### Affected Versions
Wasmi `v0.41.0` through Wasmi `v1.0.0`.
### Workarounds
- Upgrade to the latest patched version of Wasmi. - Consider limiting the maximum linear memory sizes where feasible.
### Credits
This vulnerability was discovered by **Robert T. Morris (RTM)**.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.41.0Fixed in: 0.41.2Upgrade wasmi to 0.41.2 or newer (ecosystem crates.io).
0.42.0Fixed in: 0.47.1Upgrade wasmi to 0.47.1 or newer (ecosystem crates.io).
0.50.0Fixed in: 0.51.3Upgrade wasmi to 0.51.3 or newer (ecosystem crates.io).
1.0.0Fixed in: 1.0.1Upgrade wasmi to 1.0.1 or newer (ecosystem crates.io).