CVE 8.4 HIGH

Wasmi’s Linear Memory has a Critical Use After Free Vulnerability_CVE-2025-66627

8.4 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Wasmi is a WebAssembly interpreter focused on constrained and embedded systems. In versions 0.41.0, 0.41.1, 0.42.0 through 0.47.1, 0.50.0 through 0.51.2 and 1.0.0, Wasmi's linear memory implementation leads to a Use After Free vulnerability, triggered by a WebAssembly module under certain memory growth conditions. This issue potentially leads to memory corruption, information disclosure, or code execution. This issue is fixed in versions 0.41.2, 0.47.1, 0.51.3 and 1.0.1. To workaround this issue, consider limiting the maximum linear memory sizes where feasible.

Basic Information

ID CVE-2025-66627
Source GitHub_M
Published Dec 9, 2025 at 02:52

Affected Product

Vendor wasmi-labs
Product wasmi
Version >= 0.41.0, < 0.41.2
Affected Versions wasmi-labs wasmi >= 0.41.0, < 0.41.2
wasmi-labs wasmi >= 0.42.0, < 0.47.1
wasmi-labs wasmi >= 0.50.0, < 0.51.3
wasmi-labs wasmi >= 1.0.0, < 1.0.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.