Description
Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an embedder mutates a Store in Store::epoch_deadline_callback or continues using a Store after cancellation or a trap. A cancelled non-nullable table growth can leave null elements, linear-memory growth during memory.copy can invalidate retained raw pointers, and callback-triggered garbage collection during array.copy can invalidate GC pointers, resulting in a crash, invalid memory access, or GC heap corruption. Embeddings whose callbacks only access the host data in Store<T>, and embeddings that discard a Store after timeout or epoch deadline, are not affected. This issue is fixed in versions 46.0.2 and 47.0.3.
Published: 2026-10-02
Score: 2 Low
EPSS: n/a
KEV: No
Impact: Internal VM state corruption leading to crashes, invalid memory access, or heap corruption
Action: Patch
AI Analysis

Impact

Wasmtime, a WebAssembly runtime, had a flaw in its fuel and epoch preemption checks for bulk operations such as memory.copy, table.grow, and array.copy. The issue could cause the engine to expose partially processed internal state when an embedder callback mutates the Store or continues using it after a cancellation or trap. This exposure may result in a crash, an invalid memory access, or corruption of the garbage‑collected heap, compromising the integrity of the runtime’s memory management.

Affected Systems

The vulnerability affected Wasmtime releases from 46.0.0 through 46.0.2 and the 47.0.3 release. Embedders using these versions of the bytecodealliance:wasmtime runtime are susceptible if they rely on bulk operations and their callbacks interact with the Store during preemption or post‑cancellation.

Risk and Exploitability

The CVSS score of 2 indicates low severity, and no EPSS data is available, making the likelihood of exploitation uncertain. This vulnerability is not listed in the CISA KEV catalog. The primary exploitation vector is through the embedder’s use of bulk operations and the ability to trigger preemption or cancellation logic; an attacker with control over the embedder code could trigger the flaw, but the impact revolves around local corruption rather than remote code execution. Given the limited severity metrics and absence of widespread exploitation, the risk is moderate for environments that continue to use the affected Wasmtime versions, especially if they run unpatched code that performs bulk operations.

Generated by OpenCVE AI on October 2, 2026 at 19:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Wasmtime to a fixed release, such as 46.0.2 or 47.0.3.
  • Audit embedder callbacks to ensure that Store is not mutated or accessed after preemption or cancellation during bulk operations.
  • Avoid or replace bulk operations (memory.copy, table.grow, array.copy) that trigger preemption until the upgrade is completed.

Generated by OpenCVE AI on October 2, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Bytecodealliance
Bytecodealliance wasmtime
Vendors & Products Bytecodealliance
Bytecodealliance wasmtime

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Wasmtime is a runtime for WebAssembly. From 46.0.0 until 46.0.2 and 47.0.3, fuel and epoch preemption checks inside bulk operations including memory.copy, table.grow, and array.copy can expose invalid intermediate state when an embedder mutates a Store in Store::epoch_deadline_callback or continues using a Store after cancellation or a trap. A cancelled non-nullable table growth can leave null elements, linear-memory growth during memory.copy can invalidate retained raw pointers, and callback-triggered garbage collection during array.copy can invalidate GC pointers, resulting in a crash, invalid memory access, or GC heap corruption. Embeddings whose callbacks only access the host data in Store<T>, and embeddings that discard a Store after timeout or epoch deadline, are not affected. This issue is fixed in versions 46.0.2 and 47.0.3.
Title Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state
Weaknesses CWE-362
References
Metrics cvssV4_0

{'score': 2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Bytecodealliance Wasmtime
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T17:37:50.941Z

Reserved: 2026-10-02T14:38:43.244Z

Link: CVE-2026-104855

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T18:17:02.083

Modified: 2026-10-02T18:17:02.220

Link: CVE-2026-104855

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:00:22Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')