Critical Use-After-Free in Wasmi's Linear Memory
Package
wasmi (Rust)
Affected versions
>= 0.41.0, < 0.41.2
>= 0.42.0, < 0.47.1
>= 0.50.0, < 0.51.3
>= 1.0.0, < 1.0.1
Patched versions
0.41.2
0.47.1
0.51.3
1.0.1
Description
Published to the GitHub Advisory Database Dec 8, 2025
Reviewed Dec 8, 2025
Published by the National Vulnerability DatabaseDec 9, 2025
Last updated Dec 9, 2025
Summary
A use-after-free vulnerability has been discovered in the linear memory implementation of Wasmi. This issue can be triggered by a WebAssembly module under certain memory growth conditions, potentially leading to memory corruption, information disclosure, or code execution.
Impact
Affected Versions
Wasmi
v0.41.0through Wasmiv1.0.0.Workarounds
Credits
This vulnerability was discovered by Robert T. Morris (RTM).
References