CVE-2025-64345 — Race Condition in Wasmtime
Severity
1.8LOWNVD
EPSS
0.0%
top 99.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Description
Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear memory. This is not sound for shared linear memories, which could be modified in parallel, and this could lead to a data race in the host. Patch releases have been issued for all supported versions of Was…
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:NExploitability: 0.3 | Impact: 1.4