GHSA-m9w2-8782-2946
Wasmtime has host data leakage with 64-bit tables and Winch
Details
### Impact
Wasmtime's Winch compiler contains a bug where a 64-bit table, part of the memory64 proposal of WebAssembly, incorrectly translated the `table.size` instruction. This bug could lead to disclosing data on the host's stack to WebAssembly guests. The host's stack can possibly contain sensitive data related to other host-originating operations which is not intended to be disclosed to guests.
This bug specifically arose from a mistake where the return value of `table.size` was statically typed as a 32-bit integer, as opposed to consulting the table's index type to see how large the returned register could be. When combined with details about Wnich's ABI, such as multi-value returns, this can be combined to read stack data from the host, within a guest. This information disclosure should not be possible in WebAssembly, violates spec semantics, and is a vulnerability in Wasmtime.
### Patches
Wasmtime 36.0.7, 42.0.2, and 43.0.1 have been issued to fix this bug. Users are recommended to update to these patched versions of Wasmtime.
### Workarounds
Users of Cranelift are not affected by this issue, but users of Winch have no workarounds other than disabling the `Config::wasm_memory64` proposal.
Are you affected?
Enter the version of the package you're using.
Affected packages
25.0.0Fixed in: 36.0.7Upgrade wasmtime to 36.0.7 or newer (ecosystem crates.io).
37.0.0Fixed in: 42.0.2Upgrade wasmtime to 42.0.2 or newer (ecosystem crates.io).
43.0.0Fixed in: 43.0.1Upgrade wasmtime to 43.0.1 or newer (ecosystem crates.io).