Impact
This vulnerability occurs when wasm2c fails to check the return value of calloc while allocating a funcref table. If the allocation returns NULL, the table size remains as declared, allowing bounds checks to succeed and table accesses to reference absolute memory addresses. The flaw thus permits arbitrary reading and writing of host process memory and, through table.get, table.set, and call_indirect, arbitrary code execution. This breaks sandbox isolation and is classified as CWE‑252.
Affected Systems
The issue affects WebAssembly wabt up to and including version 1.0.41. Any application that embeds wabt for sandboxed execution – such as RLBox, WasmBoxC, and Firefox where libraries like Graphite, Hunspell, Ogg, Expat, and Woff2 are compiled via wasm2c – is potentially impacted. Untrusted WebAssembly code running in those environments could exploit the defect.
Risk and Exploitability
The CVSS base score is 7.1, indicating high severity. EPSS is below 1% and the vulnerability is not in the CISA KEV list. Exploitation requires a calloc failure, which can occur under low‑memory conditions, address‑space limits, non‑overcommit settings, or on 32‑bit hosts. When triggered, an attacker can escape the sandbox and execute code, so the risk is significant in affected deployments. On 64‑bit Linux with default overcommit the allocation succeeds and the defect is not triggered.
OpenCVE Enrichment