Wasmtime vulnerable to data leakage between instances in the pooling allocator
CVE-2022-39393
What is CVE-2022-39393?
Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance. This bug has been patched and users should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include disabling the pooling allocator and disabling the memory-init-cow.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wasmtime >= 2.0.0, < 2.0.2 < 2.0.0, 2.0.2
wasmtime < 1.0.2 < 1.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
