WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in WasmEdge/include/runtime/instance/memory.h can wrap, causing checkAccessBound() to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-190"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69261.json"
}{
"cpe": "cpe:2.3:a:linuxfoundation:wasmedge:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.16.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69261.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"321841578989354777447708724282533735910",
"89818731103215995964617571996520816119",
"2613939707723102598886305993665912785",
"236303773334839303174194088992119663602",
"213936535720176606448703368750349849170",
"243716784187250461111155335855917975759",
"310252924324522487897276047135395880643",
"89108753120962946307626765540039998575",
"113067996317145965491398072766830351773",
"14580826971662117960887407870935664645"
],
"threshold": 0.9
},
"id": "CVE-2025-69261-693471d6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/wasmedge/wasmedge/commit/37cc9fa19bd23edbbdaa9252059b17f191fa4d17",
"target": {
"file": "include/runtime/instance/memory.h"
}
}
]
"2026-08-12T15:14:58Z"