Use-After-Free Vulnerability in wasm3 Affected by Development Issues
CVE-2024-27530

8.4HIGH

Key Information:

Vendor

wasm3

Status
Vendor
CVE Published:
8 November 2024

What is CVE-2024-27530?

The wasm3 project has identified a use-after-free vulnerability in version 139076a, which arises from improper memory management during the ForEachModule process. This flaw can potentially lead to unexpected behavior or security risks in applications utilizing this WebAssembly interpreter, opening avenues for exploits that could compromise system integrity. Developers using the affected version are encouraged to review their integration of wasm3 and consider upgrading to mitigate any potential risks.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.