PT-2025-52497 · Unknown+1 · Webassembly Binaryen+1
Oneafter
·
Published
2025-12-19
·
Updated
2025-12-30
·
CVE-2025-14957
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
WebAssembly Binaryen versions prior to 126
Description
A flaw exists in the
IRBuilder component of WebAssembly Binaryen. Specifically, the functions IRBuilder::makeLocalGet, IRBuilder::makeLocalSet, and IRBuilder::makeLocalTee within the src/wasm/wasm-ir-builder.cpp file are susceptible to a null pointer dereference due to manipulation of the Index argument. Local access is required for exploitation. The exploit is publicly available.Recommendations
Apply the patch 6fb2b917a79578ab44cf3b900a6da4c27251e0d4.
Exploit
Fix
Improper Resource Release
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Webassembly Binaryen