PT-2026-31685 · Bytecode Alliance · Wasmtime

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2026-34944

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wasmtime versions prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1
Description Wasmtime, a runtime for WebAssembly, may experience an uncaught segfault on x86-64 platforms with SSE3 disabled when compiling the f64x2.splat WebAssembly instruction with Cranelift. This occurs when signals-based-traps are disabled, potentially leading to a denial-of-service condition. The issue involves loading 8 more bytes than necessary, which can result in loading from unmapped guard pages. While the loaded data is not directly visible to WebAssembly guests, disabling signals-based-traps and enabling guard pages can cause the host process to terminate.
Recommendations Update to Wasmtime version 24.0.7, 36.0.7, 42.0.2, or 43.0.1.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-34944
GHSA-QQFJ-4VCM-26HV
RUSTSEC-2026-0087

Affected Products

Wasmtime