PT-2025-52497 · Unknown+1 · Webassembly Binaryen+1

Oneafter

·

Published

2025-12-19

·

Updated

2025-12-30

·

CVE-2025-14957

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WebAssembly Binaryen versions prior to 126
Description A flaw exists in the IRBuilder component of WebAssembly Binaryen. Specifically, the functions IRBuilder::makeLocalGet, IRBuilder::makeLocalSet, and IRBuilder::makeLocalTee within the src/wasm/wasm-ir-builder.cpp file are susceptible to a null pointer dereference due to manipulation of the Index argument. Local access is required for exploitation. The exploit is publicly available.
Recommendations Apply the patch 6fb2b917a79578ab44cf3b900a6da4c27251e0d4.

Exploit

Fix

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-14957

Affected Products

Debian
Webassembly Binaryen