Description
wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus, bounds checks still pass and table element accesses resolve to absolute memory addresses (i * sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of host process memory and - via table.get, table.set, and call_indirect - arbitrary code execution, defeating the isolation that wasm2c exists to provide (a full sandbox escape). wasm2c is used as an in-process sandboxing boundary by RLBox and WasmBoxC, including in Firefox, which compiles the Graphite, Hunspell, Ogg, Expat, and Woff2 libraries via wasm2c to contain untrusted font, media, and XML input. Therefore, sandboxing in these applications is potentially affected. Exploitation requires the funcref table allocation to fail, for example under an address-space limit (RLIMIT_AS), on 32-bit hosts, with vm.overcommit_memory=2, or under memory pressure. On 64-bit Linux with default overcommit the allocation succeeds and the defect is not triggered. The wasm2c memory allocator aborts on calloc failure in the same runtime; the table allocator lacks this abort behavior. This was introduced in commit ab9e0b55 (PR #813).
Published: 2026-09-12
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Code Execution via sandbox escape
Action: Apply Patch
AI Analysis

Impact

This vulnerability occurs when wasm2c fails to check the return value of calloc while allocating a funcref table. If the allocation returns NULL, the table size remains as declared, allowing bounds checks to succeed and table accesses to reference absolute memory addresses. The flaw thus permits arbitrary reading and writing of host process memory and, through table.get, table.set, and call_indirect, arbitrary code execution. This breaks sandbox isolation and is classified as CWE‑252.

Affected Systems

The issue affects WebAssembly wabt up to and including version 1.0.41. Any application that embeds wabt for sandboxed execution – such as RLBox, WasmBoxC, and Firefox where libraries like Graphite, Hunspell, Ogg, Expat, and Woff2 are compiled via wasm2c – is potentially impacted. Untrusted WebAssembly code running in those environments could exploit the defect.

Risk and Exploitability

The CVSS base score is 7.1, indicating high severity. EPSS is below 1% and the vulnerability is not in the CISA KEV list. Exploitation requires a calloc failure, which can occur under low‑memory conditions, address‑space limits, non‑overcommit settings, or on 32‑bit hosts. When triggered, an attacker can escape the sandbox and execute code, so the risk is significant in affected deployments. On 64‑bit Linux with default overcommit the allocation succeeds and the defect is not triggered.

Generated by OpenCVE AI on September 15, 2026 at 18:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WebAssembly wabt to a patched version that validates the calloc return value.
  • Upgrade RLBox, WasmBoxC, and Firefox components that use wabt to the latest patched releases so that sandbox boundaries remain intact.
  • If an upgrade cannot be applied immediately, disable untrusted WebAssembly execution in the affected applications or isolate the sandboxed code in a separate process to limit the impact of a potential escape.

Generated by OpenCVE AI on September 15, 2026 at 18:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title wasm2c Funcref Table Allocation Failure Enables Code Execution

Tue, 15 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title wasm2c Funcref Table Allocation Failure Enables Code Execution

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Wasm2c Sandbox Escape via Table Allocation Failure on 32‑bit Platforms
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Wasm2c Sandbox Escape via Table Allocation Failure on 32‑bit Platforms

Sun, 13 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title wasm2c Funcref Table Allocation Failure Enabling Sandbox Escape

Sun, 13 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title wasm2c Funcref Table Allocation Failure Enabling Sandbox Escape

Sat, 12 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a "table flip" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus, bounds checks still pass and table element accesses resolve to absolute memory addresses (i * sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of host process memory and - via table.get, table.set, and call_indirect - arbitrary code execution, defeating the isolation that wasm2c exists to provide (a full sandbox escape). wasm2c is used as an in-process sandboxing boundary by RLBox and WasmBoxC, including in Firefox, which compiles the Graphite, Hunspell, Ogg, Expat, and Woff2 libraries via wasm2c to contain untrusted font, media, and XML input. Therefore, sandboxing in these applications is potentially affected. Exploitation requires the funcref table allocation to fail, for example under an address-space limit (RLIMIT_AS), on 32-bit hosts, with vm.overcommit_memory=2, or under memory pressure. On 64-bit Linux with default overcommit the allocation succeeds and the defect is not triggered. The wasm2c memory allocator aborts on calloc failure in the same runtime; the table allocator lacks this abort behavior. This was introduced in commit ab9e0b55 (PR #813).
First Time appeared Webassembly
Webassembly wabt
Weaknesses CWE-252
CPEs cpe:2.3:a:webassembly:wabt:*:*:*:*:*:*:*:*
Vendors & Products Webassembly
Webassembly wabt
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}


Subscriptions

Webassembly Wabt
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:16:43.958Z

Reserved: 2026-09-12T23:16:33.768Z

Link: CVE-2026-90648

cve-icon Vulnrichment

Updated: 2026-09-14T16:16:40.448Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T00:17:07.023

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-90648

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses