PT-2025-12406 · Unknown+1 · Webassembly Wabt+1

Published

2025-03-21

·

Updated

2025-11-25

·

CVE-2025-2584

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions WebAssembly wabt version 1.0.36
Description A critical vulnerability was found in WebAssembly wabt, affecting the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipulation leads to a heap-based buffer overflow. The attack can be initiated remotely, and the complexity of the attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
Recommendations As a temporary workaround, consider disabling the BinaryReaderInterp::GetReturnCallDropKeepCount function until a patch is available. Restrict access to the vulnerable file wabt/src/interp/binary-reader-interp.cc to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2584
PYSEC-2025-228

Affected Products

Debian
Webassembly Wabt