Wasmtime, Bulk Memory Operation State Corruption, CVE-2025-59531 (High) -DC-Oct2026-2714

Listen to this Post

to CVE-2025-59531

Wasmtime’s implementation of bulk-data-transfer WebAssembly instructions, such as memory.copy, table.grow, and array.copy, contains a vulnerability when a preemption via epochs or fuel is combined with altering the store’s state or cancelling a computation. To prevent these operations from taking too long, Wasmtime injects fuel/epoch checks during these operations, but this enables embedders, and possibly WebAssembly, to witness intermediate state in the middle of the operation.
The vulnerability manifests in three distinct scenarios. First, when a non-nullable WebAssembly table is grown, the new elements initially start as null and are filled in as part of a loop with preemption checks. If this computation is then cancelled, the table is left in a grown-but-uninitialized state where subsequent usage via WebAssembly could possibly segfault. Loads from this table are assumed to not be null due to its type, but the runtime implementation was exposed through this cancellation at a preemption point.
Second, embedders could mutate the store during an epoch callback, such as growing a WebAssembly linear memory. During a bulk `memory.copy` operation, the pointers being copied to/from weren’t recomputed between preemption points. This meant that if the linear memory moved its base address, it could be possible to have a preemption, the embedder manually grows memory, and then on resumption the copy operation uses invalid pointers.
Third, embedders could execute a garbage collection during epoch callbacks. GC operations such as array.copy, like `memory.copy` above, maintained raw pointers internally in the operation which were not updated after the preemption point. This could lead to corruption of the GC heap.
All of these situations are examples of embedder-driven mutations of the `Store` or embedder-induced resumption of a `Store` after a computation was cancelled. These operations expose the internal state of these WebAssembly operations, which is semantically incorrect and additionally can cause segfaults. Exposing these bugs, however, requires explicit patterns to be present in the embedding itself, such as using `Store::epoch_deadline_callback` and mutating wasm options. Another example is to cancel one invocation (possibly in a table.grow) and then execute more wasm afterwards within the same store. Embeddings not using `Store::epoch_deadline_callback` or executing code after timeouts/fuel are not affected by this issue.

DailyCVE Form:

Platform: Wasmtime
Version: 46.0.2/47.0.3
Vulnerability: State Corruption
Severity: High
date: 2026-10-03

Prediction: 2025-09-24

What Undercode Say

Analytics

Check Wasmtime version
wasmtime --version
Audit Cargo dependencies for Wasmtime
cargo audit | grep wasmtime
Verify Wasmtime crate version in Cargo.lock
grep -A2 'name = "wasmtime"' Cargo.lock
Check for vulnerable epoch callback usage in codebase
grep -rn "epoch_deadline_callback" --include=".rs" .
Inspect Wasmtime changelog for patch details
curl -s https://raw.githubusercontent.com/bytecodealliance/wasmtime/main/RELEASES.md | head -100
// Vulnerable pattern: mutating store in epoch callback
store.epoch_deadline_callback(|mut store| {
// DANGER: Growing memory during epoch callback
let mem = store.get_export("memory").unwrap();
// This mutation during preemption causes invalid pointers
Ok(UpdateDeadline::Continue(1))
});
// Safe pattern: only access T in Store<T>
store.epoch_deadline_callback(|store| {
let data = store.data();
// Only read embedder data, no wasm mutation
Ok(UpdateDeadline::Continue(1))
});

Exploit: (Educational Purposes!)

use wasmtime::;
fn main() -> Result<()> {
let engine = Engine::default();
let module = Module::from_file(&engine, "bulk_memory.wasm")?;
let mut store = Store::new(&engine, ());
store.set_epoch_deadline(1);
// Exploit: Cancel at preemption point in table.grow
store.epoch_deadline_callback(|_store| {
// Cancelling computation mid-operation
Err(anyhow::anyhow!("Cancelled"))
});
let instance = Instance::new(&mut store, &module, &[])?;
let table = instance.get_table(&mut store, "table").unwrap();
// Trigger table.grow which will be cancelled mid-operation
let _ = table.grow(&mut store, 1000, Val::I32(42));
// Table now in grown-but-uninitialized state
// Subsequent access may segfault
Ok(())
}
Compile and run exploit demonstration
cargo build --release
./target/release/wasmtime_exploit

Protection: from this CVE

// Protection 1: Update to patched versions
// In Cargo.toml
[bash]
wasmtime = "46.0.2" or "47.0.3"
// Protection 2: Avoid mutating store in epoch callbacks
store.epoch_deadline_callback(|store| {
// SAFE: Only access embedder data T in Store<T>
let embedder_data: &MyData = store.data();
if embedder_data.should_timeout() {
return Err(anyhow::anyhow!("Timeout"));
}
Ok(UpdateDeadline::Continue(1))
});
// Protection 3: Do not resume wasm after trapping
match instance.get_func(&mut store, "run") {
Some(func) => {
match func.call(&mut store, &[], &mut []) {
Ok(<em>) => {}
Err(</em>) => {
// SAFE: Drop the store instead of resuming
drop(store);
return Ok(());
}
}
}
None => {}
}
Protection 4: Verify patch is applied
cargo update -p wasmtime
cargo tree | grep wasmtime
Expected output:
wasmtime v46.0.2

Impact:

  • Segmentation Faults: Grown-but-uninitialized tables with non-nullable types cause memory access violations
  • Memory Corruption: Invalid pointers used in `memory.copy` after linear memory relocation during epoch callback
  • GC Heap Corruption: Stale raw pointers in `array.copy` operations after GC executes during preemption
  • Semantic Violations: Internal state exposure of WebAssembly operations that should be atomic
  • Denial of Service: Embedders can trigger crashes through epoch callback misuse
  • Affected Components: memory.copy, memory.fill, table.grow, table.copy, array.copy, `array.fill`
    – Affected Versions: Wasmtime 46.0.0-46.0.1 and 47.0.0-47.0.2
  • Fixed Versions: Wasmtime 46.0.2 and 47.0.3

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top