CVE-2025-62711
24.10.2025, 22:15
Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which when called in a specific way, would crash the host with a segfault or assert failure. Wasmtime 38.0.3 has been released and is patched to fix this issue. There are no workarounds.Enginsight
| Vendor | Product | Version |
|---|---|---|
| bytecodealliance | wasmtime | 38.0.0 ≤ 𝑥 < 38.0.3 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration