Out-of-Bounds Array Access in WebAssembly Micro Runtime by Bytecode Alliance
CVE-2025-64713
What is CVE-2025-64713?
A vulnerability in the WebAssembly Micro Runtime (WAMR) affects its fast interpreter mode during WASM bytecode loading. If the arrays frame_ref_bottom and frame_offset_bottom reach capacity while processing GET_GLOBAL(I32) opcodes, an improper handling may lead to out-of-bounds access. This situation arises when frame_ref_bottom is expanded, but frame_offset_bottom is neglected. This issue manifests particularly when subsequent opcodes are executed, resulting in potential access to invalid memory areas. The vulnerability has been addressed in version 2.4.4, which users are encouraged to upgrade to in order to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wasm-micro-runtime < 2.4.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
