PT-2025-54223 · Wasmedge+1 · Wasmedge+1

Robert Morris

·

Published

2025-01-01

·

Updated

2026-03-09

·

CVE-2025-69261

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WasmEdge versions prior to 0.16.0-alpha.3
Description WasmEdge is a WebAssembly runtime. A multiplication operation within WasmEdge/include/runtime/instance/memory.h can result in a wrap-around, leading the checkAccessBound() function to incorrectly permit memory access. This condition can trigger a segmentation fault.
Recommendations Update to version 0.16.0-alpha.3 or later.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-69261
GHSA-89FM-8MR7-GG4M

Affected Products

Debian
Wasmedge