PT-2025-11458 · Unknown+1 · Webassembly Wabt+1

Published

2025-03-17

·

Updated

2026-01-06

·

CVE-2025-2368

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebAssembly wabt version 1.0.36
Description A critical issue affects the function wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport of the component Malformed File Handler, leading to a heap-based buffer overflow. The attack may be initiated remotely. This issue is related to the file wabt/src/interp/binary-reader-interp.cc.
Recommendations Apply a patch to fix this issue for WebAssembly wabt version 1.0.36. As a temporary workaround, consider restricting access to the OnExport function of the BinaryReaderInterp class until a patch is available.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-2368
PYSEC-2025-227

Affected Products

Debian
Webassembly Wabt