Back

MEDIUM

WasmEdge integer wrap in MemoryInstance::getSpan()'s memory size check

Published Dec 30, 2025

Description

WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Moderate for Red Hat products as it leads to a Denial of Service in WasmEdge. A remote attacker can trigger a segmentation fault by exploiting an incorrect memory access within the `checkAccessBound()` function. This affects WasmEdge in Community Projects (EPEL, Fedora) and OpenShift Container Platform, potentially causing the runtime to crash.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 30, 2025
Updated Jan 2, 2026
Reserved Dec 30, 2025
CISA Vulnrichment
Updated Jan 2, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 30, 2025
ENISA EUVD
Assigner GitHub_M
Published Dec 30, 2025
Updated Jan 2, 2026
Exploited since n/a
EUVD-2025-205847