OSV-2025-230

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/wamr/OSV-2025-230.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2025-230
Published
2025-03-22T00:05:22.916187Z
Modified
2025-03-22T00:05:22.916485Z
Summary
Heap-buffer-overflow in wasm_loader_prepare_bytecode
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=404921047

Crash type: Heap-buffer-overflow WRITE 8
Crash state:
wasm_loader_prepare_bytecode
load_from_sections
wasm_loader_load
References

Affected packages

OSS-Fuzz / wamr

Package

Name
wamr
Purl
pkg:generic/wamr

Affected ranges

Type
GIT
Repo
https://github.com/bytecodealliance/wasm-micro-runtime
Events

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

{
    "introduced_range": "c30e65ba5d2bb4c1b96e23dfaa74e498fc3ac3a3:06ea960e76d49fcab7342541bde2329e25287520",
    "fixed_range": "79f26a96a47bbce8a9f17ba284be4625eca8e265:9aaf3599ec69469f6ab3b4373bfb0d8e6b3345b9"
}