Memory Management Flaw in WebAssembly Micro Runtime by Bytecode Alliance
CVE-2023-52284
5.5MEDIUM
What is CVE-2023-52284?
The wasm-micro-runtime, developed by Bytecode Alliance, has a vulnerability that allows for a 'double free or corruption' scenario when processing valid WebAssembly modules. This issue arises from improper handling of the push_pop_frame_ref_offset, which can lead to instability and potential exploitation of the runtime environment. Users should consider upgrading to version 1.3.0 or later to mitigate this risk.
