Vulnerability GHSA-hc7m-r6v8-hg9q: Information
Description
Wasmtime provides unsound API access to a WebAssembly shared linear memory
Severity: LOW (1.8)
Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
|---|---|---|---|---|---|---|
| wasmtime | sisyphus | 43.0.0-alt1 | 43.0.0-alt1 | ALT-PU-2026-5689-2 | 414049 | Fixed |
| wasmtime | sisyphus_riscv64 | 43.0.0-alt1 | 43.0.0-alt1 | ALT-PU-2026-7613-1 | - | Fixed |
| wasmtime | sisyphus_loongarch64 | 43.0.0-alt1 | 43.0.0-alt1 | ALT-PU-2026-7551-1 | - | Fixed |
Affected packages
Ecosystem | Name | Affected versions | Patched versions |
|---|---|---|---|
| crates.io | wasmtime | >=38.0.0, <38.0.4 >=37.0.0, <37.0.3 >=26.0.0, <36.0.3 <24.0.5 | 38.0.4 37.0.3 36.0.3 24.0.5 |