cve/2024/CVE-2024-30266.md
2024-05-25 21:48:12 +02:00

18 lines
906 B
Markdown

### [CVE-2024-30266](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-30266)
![](https://img.shields.io/static/v1?label=Product&message=wasmtime&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20%3D%2019.0.0%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-843%3A%20Access%20of%20Resource%20Using%20Incompatible%20Type%20('Type%20Confusion')&color=brighgreen)
### Description
wasmtime is a runtime for WebAssembly. The 19.0.0 release of Wasmtime contains a regression introduced during its development which can lead to a guest WebAssembly module causing a panic in the host runtime. A valid WebAssembly module, when executed at runtime, may cause this panic. This vulnerability has been patched in version 19.0.1.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/fkie-cad/nvd-json-data-feeds