WasmEdge integer wrap in MemoryInstance::getSpan()'s memory size check
Published Dec 30, 2025
5.5
MEDIUMCVSS 4.0
EPSS 0.33%
Description
WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue.
Affected products
-
- Version < 0.16.0-alpha.3StatusaffectedConstraints-
- Version
- < 0.16.0
- 0.16.0
- 0.16.0
No data.
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
Red Hat OpenShift Container Platform 4
wasmedge
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | wasmedge | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated Moderate for Red Hat products as it leads to a Denial of Service in WasmEdge. A remote attacker can trigger a segmentation fault by exploiting an incorrect memory access within the `checkAccessBound()` function. This affects WasmEdge in Community Projects (EPEL, Fedora) and OpenShift Container Platform, potentially causing the runtime to crash.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2025-69261 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2426308 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205847 Advisory
- https://github.com/WasmEdge/WasmEdge/commit/37cc9fa19bd23edbbdaa9252059b17f191fa4d17 x_refsource_MISCPatch
- https://github.com/WasmEdge/WasmEdge/security/advisories/GHSA-89fm-8mr7-gg4m x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-69261
- https://www.cve.org/CVERecord?id=CVE-2025-69261
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-69261 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2426308 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-205847 | Advisory | |
| https://github.com/WasmEdge/WasmEdge/commit/37cc9fa19bd23edbbdaa9252059b17f191fa4d17 | x_refsource_MISCPatch | |
| https://github.com/WasmEdge/WasmEdge/security/advisories/GHSA-89fm-8mr7-gg4m | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-69261 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-69261 |
Change history (0)
No recorded changes yet.