Critical Use-After-Free in Wasmi's Linear Memory
Package
Affected versions
>= 0.41.0, < 0.41.2
>= 0.42.0, < 0.47.1
>= 0.50.0, < 0.51.3
>= 1.0.0, < 1.0.1
Patched versions
0.41.2
0.47.1
0.51.3
1.0.1
Description
Published to the GitHub Advisory Database
Dec 8, 2025
Reviewed
Dec 8, 2025
Published by the National Vulnerability Database
Dec 9, 2025
Last updated
Dec 9, 2025
Summary
A use-after-free vulnerability has been discovered in the linear memory implementation of Wasmi. This issue can be triggered by a WebAssembly module under certain memory growth conditions, potentially leading to memory corruption, information disclosure, or code execution.
Impact
Affected Versions
Wasmi
v0.41.0through Wasmiv1.0.0.Workarounds
Credits
This vulnerability was discovered by Robert T. Morris (RTM).
References