Listen to this Post
The vulnerability in Wasmtime 38.0.0 through 38.0.2 stems from an incomplete refactoring of host-to-wasm trampolines that removed setjmp/longjmp for stack unwinding. Specifically, the trampolines for component-model intrinsics were not updated alongside all others. Consequently, these specific trampolines fail to set crucial runtime data structures, such as the trap handler’s destination address. If an error occurs during the execution of a WebAssembly function that uses one of these missing trampolines, the runtime attempts to read the uninitialized data. A key piece of this data, the trap pointer, is left as a null (0) value. This causes the host process to jump to address 0 when a trap occurs, resulting in a deterministic segmentation fault and a crash of the WebAssembly runtime. Exploiting this requires a meticulously crafted component that directly uses component intrinsics like `resource.rep` with specific type signatures, making real-world exploitation complex but leading to a reliable denial-of-service.
Platform: Wasmtime
Version: 38.0.0-38.0.2
Vulnerability: Memory Corruption
Severity: Critical
date: 2025-10-24
Prediction: 2025-10-24
What Undercode Say:
cargo update wasmtime
// Hypothetical component triggering the bug // This would not be generated by standard toolchains. (component (import "host" "func" (func $host_func (param resource))) (core func $host_func (canon lift resource.rep ...)) )
How Exploit:
Craft a malicious WebAssembly component that directly uses a component-model intrinsic like resource.rep. The host must then invoke a function from this component that matches the specific type signature requiring the flawed intrinsic trampoline. Upon invocation and subsequent error/trap, the runtime will dereference a null trap pointer, crashing the process.
Protection from this CVE:
Upgrade to Wasmtime version 38.0.3 immediately. For versions 38.0.0 to 38.0.2, there are no effective workarounds; updating is the only solution. Using only core WebAssembly modules instead of components also mitigates the risk, as the vulnerable trampolines are exclusive to the component model.
Impact:
Denial-of-Service (DoS) through a deterministic host crash (segmentation fault or assert failure) when a specifically crafted component is executed under specific conditions. This violates Wasmtime’s safety guarantee that safe Rust code should not be able to crash the runtime.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

