CVE 4.8 MEDIUM

wasm3 m3_exec.h op_CallIndirect memory corruption_CVE-2025-15413

4.8 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was detected in wasm3 up to 0.5.0. Impacted is the function op_SetSlot_i32/op_CallIndirect of the file m3_exec.h. Performing manipulation results in memory corruption. The attack needs to be approached locally. The exploit is now public and may be used. Unfortunately, the project has no active maintainer at the moment.

Basic Information

ID CVE-2025-15413
Source VulDB
Published Jan 1, 2026 at 21:02

Affected Product

Vendor n/a
Product wasm3
Version 0.1
Affected Versions n/a wasm3 0.1
n/a wasm3 0.2
n/a wasm3 0.3
n/a wasm3 0.4
n/a wasm3 0.5.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.