cbcvebase.

Debian Rust-Wasmtime vulnerabilities

8 known vulnerabilities affecting debian/rust-wasmtime.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
MEDIUM3LOW5

Vulnerabilities

Page 1 of 1
CVE-2024-47763P4MEDIUMCVSS 5.5Exploitedfixed in rust-wasmtime 21.0.2+dfsg-1 (forky)2024
CVE-2024-47763 [MEDIUM] CVE-2024-47763: rust-wasmtime - Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of... Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in certain WebAssembly modules. The runtime crash may be undefined behavior if Wasmtime was compiled with Rust 1.80 or prior. The runtime crash is a deterministic process abort when Wasmtime is compi
debian
CVE-2024-51745P2LOWCVSS 2.3fixed in rust-wasmtime 26.0.1+dfsg-1 (forky)2024
CVE-2024-51745 [LOW] CVE-2024-51745: rust-wasmtime - Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem san... Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", "LPT0", "LPT1", and so on, however it did not block access to the special device filenames which use superscript digits, such as "COM¹", "COM²", "LPT⁰", "LPT¹", and so on. Untrusted Wasm
debian
CVE-2026-27572P3MEDIUMCVSS 6.9fixed in rust-wasmtime 36.0.6+dfsg-1 (forky)2026
CVE-2026-27572 [MEDIUM] CVE-2026-27572: rust-wasmtime - Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04,... Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of the `wasi:http/types.fields` resource is susceptible to panics when too many fields are added to the set of headers. Wasmtime's implementation in the `wasmtime-wasi-http` crate is backed by a data structure which panics when it re
debian
CVE-2026-27204P3MEDIUMCVSS 6.9fixed in rust-wasmtime 36.0.6+dfsg-1 (forky)2026
CVE-2026-27204 [MEDIUM] CVE-2026-27204: rust-wasmtime - Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04,... Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.6, 36.0.6, 4.0.04, 41.0.4, and 42.0.0, Wasmtime's implementation of WASI host interfaces are susceptible to guest-controlled resource exhaustion on the host. Wasmtime did not appropriately place limits on resource allocations requested by the guests. This serves as a Denial of Service vector. Wasm
debian
CVE-2023-41880P4LOWCVSS 2.2fixed in rust-wasmtime 15.0.0+dfsg-1 (forky)2023
CVE-2023-41880 [LOW] CVE-2023-41880: rust-wasmtime - Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 ... Wasmtime is a standalone runtime for WebAssembly. Wasmtime versions from 10.0.0 to versions 10.02, 11.0.2, and 12.0.1 contain a miscompilation of the WebAssembly `i64x2.shr_s` instruction on x86_64 platforms when the shift amount is a constant value that is larger than 32. Only x86_64 is affected so all other targets are not affected by this. The miscompilation
debian
CVE-2024-30266P4LOWCVSS 3.3fixed in rust-wasmtime 21.0.2+dfsg-1 (forky)2024
CVE-2024-30266 [LOW] CVE-2024-30266: rust-wasmtime - wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a... wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1. Scope: local forky: reso
debian
CVE-2024-47813P4LOWCVSS 2.9fixed in rust-wasmtime 21.0.2+dfsg-1 (forky)2024
CVE-2024-47813 [LOW] CVE-2024-47813: rust-wasmtime - Wasmtime is an open source runtime for WebAssembly. Under certain concurrent eve... Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to a race condition, leading to panics and potentially type registry corruption. That registry corruption could, following an additional and particular sequence of concurren
debian
CVE-2025-64345P4LOWCVSS 1.8fixed in rust-wasmtime 27.0.0+dfsg-2 (forky)2025
CVE-2025-64345 [LOW] CVE-2025-64345: rust-wasmtime - Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, ... Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound interaction where a WebAssembly shared linear memory could be viewed as a type which provides safe access to the host (Rust) to the contents of the linear memory. This is not sound for shared linear memories, which could b
debian
Debian Rust-Wasmtime vulnerabilities | cvebase