Skip to content

RUSTSEC-2022-0075: Bug in pooling instance allocator #4292

@github-actions

Description

@github-actions

Bug in pooling instance allocator

Details
Package wasmtime
Version 0.27.0
URL GHSA-wh6w-3828-g9qf
Date 2022-11-10
Patched versions >=1.0.2, <2.0.0,>=2.0.2

bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be visible, erroneously to the next instance.

Mitigations are described here.

See advisory page for additional details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    StalebugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions