Back

LOW

Capstone WASM `br_table` instruction-size truncation can cause no-progress disassembly and parser desynchronization

Published Aug 14, 2026

Description

Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_table` instruction, the WASM decoder accumulates the immediate length in a wider local variable but returns it through a `uint16_t` instruction-size path. When the encoded instruction length is exactly 65,536 bytes, the size wraps to zero and `cs_disasm()` can repeatedly decode the same instruction without advancing. For larger lengths, `cs_disasm_iter()` advances into the middle of the `br_table` payload and decodes target bytes as subsequent instructions. This is an availability and parser-integrity issue. Version 6.0.0-Alpha9 patches the issue.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 14, 2026
Updated Aug 17, 2026
Reserved May 28, 2026

CISA Vulnrichment

Updated Aug 17, 2026

NVD

Status Awaiting Analysis
Modified Sep 18, 2026

Red Hat

Severity Moderate
Public date Aug 14, 2026
Bugzilla 2516114

ENISA EUVD

Assigner GitHub_M
Published Aug 14, 2026
Updated Aug 17, 2026

GitHub

No data