CVE-2024-30266

EUVD-2024-1137
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1.
Type Confusion
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 24.17%
Affected Products (NVD)
VendorProductVersion
bytecodealliancewasmtime
19.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rust-wasmtime
forky
36.0.12+dfsg-2
fixed
sid
36.0.12+dfsg-2
fixed
trixie
26.0.1+dfsg-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rust-wasmtime
focal
dne
jammy
dne
noble
needs-triage
oracular
ignored
plucky
not-affected
questing
not-affected
resolute
not-affected