Impact
Wasmtime, a WebAssembly runtime, had a flaw in its fuel and epoch preemption checks for bulk operations such as memory.copy, table.grow, and array.copy. The issue could cause the engine to expose partially processed internal state when an embedder callback mutates the Store or continues using it after a cancellation or trap. This exposure may result in a crash, an invalid memory access, or corruption of the garbage‑collected heap, compromising the integrity of the runtime’s memory management.
Affected Systems
The vulnerability affected Wasmtime releases from 46.0.0 through 46.0.2 and the 47.0.3 release. Embedders using these versions of the bytecodealliance:wasmtime runtime are susceptible if they rely on bulk operations and their callbacks interact with the Store during preemption or post‑cancellation.
Risk and Exploitability
The CVSS score of 2 indicates low severity, and no EPSS data is available, making the likelihood of exploitation uncertain. This vulnerability is not listed in the CISA KEV catalog. The primary exploitation vector is through the embedder’s use of bulk operations and the ability to trigger preemption or cancellation logic; an attacker with control over the embedder code could trigger the flaw, but the impact revolves around local corruption rather than remote code execution. Given the limited severity metrics and absence of widespread exploitation, the risk is moderate for environments that continue to use the affected Wasmtime versions, especially if they run unpatched code that performs bulk operations.
OpenCVE Enrichment