{"id":"CVE-2025-14957","summary":"WebAssembly Binaryen IRBuilder wasm-ir-builder.cpp makeLocalTee null pointer dereference","details":"A vulnerability was identified in WebAssembly Binaryen up to 125. This affects the function IRBuilder::makeLocalGet/IRBuilder::makeLocalSet/IRBuilder::makeLocalTee of the file src/wasm/wasm-ir-builder.cpp of the component IRBuilder. Such manipulation of the argument Index leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is 6fb2b917a79578ab44cf3b900a6da4c27251e0d4. Applying a patch is advised to resolve this issue.","modified":"2026-08-12T15:13:42.810305Z","published":"2025-12-19T17:02:16.843Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-404","CWE-476"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14957.json"},"references":[{"type":"WEB","url":"https://github.com/WebAssembly/binaryen/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14957.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14957"},{"type":"ADVISORY","url":"https://vuldb.com/?id.337593"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.717317"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.717319"},{"type":"REPORT","url":"https://github.com/WebAssembly/binaryen/issues/8090"},{"type":"REPORT","url":"https://github.com/WebAssembly/binaryen/pull/8099"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.337593"},{"type":"FIX","url":"https://github.com/WebAssembly/binaryen/commit/6fb2b917a79578ab44cf3b900a6da4c27251e0d4"},{"type":"EVIDENCE","url":"https://github.com/oneafter/1204/blob/main/af1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/webassembly/binaryen","events":[{"introduced":"0"},{"fixed":"6fb2b917a79578ab44cf3b900a6da4c27251e0d4"}],"database_specific":{"cpe":"cpe:2.3:a:webassembly:binaryen:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"125"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["125","version_125","version_124","version_123","version_122","version_121","rebuild-121","version_120_b","version_120","version_119","version_118","version_117","version_116","version_115","version_114","version_113","version_112","version_111","version_110","version_109","version_108","version_107","version_106","version_105","version_104","version_103","version_102","version_101","version_100","version_99","version_98","version_97","version_96","version_95","version_94","version_93","version_92","version_91","version_90","1.39.1","1.38.48","1.38.47","version_89","version_88","version_87","version_86","version_85","1.38.32","version_84","version_83","1.38.31","version_82","version_81","version_80","version_79","version_78","version_77","version_76","version_75","version_74","1.38.30","version_73","1.38.29","version_72","version_71","version_70","version_69","1.38.28","version_68","1.38.27","1.38.26","version_67","version_66","version_65","1.38.25","version_64","1.38.24","1.38.23","1.38.22","version_63","version_62","version_61","version_60","version_59","version_58","version_57","version_56","1.38.21","version_55","1.38.20","1.38.19","version_54","1.38.18","1.38.17","version_53","1.38.16","version_52","1.38.15","1.38.14","1.38.13","version_51","1.38.12","version_50","1.38.11","1.38.10","1.38.9","version_49","1.38.8","1.38.7","1.38.6","1.38.5","1.38.4","version_48","1.38.3","1.38.2","1.38.1","version_47","1.38.0","1.37.40","1.37.39","version_46","1.37.37","version_45","1.37.36","1.37.35","version_44","1.37.34","version_43","1.37.33","1.37.32","1.37.31","1.37.30","1.37.29","version_42","version_41","1.37.28","1.37.27","1.37.26","1.37.25","version_40","1.37.24","1.37.23","version_39","1.37.22","version_38","version_37","1.37.21","version_36","version_35","1.37.20","version_34","1.37.19","1.37.18","1.37.17","1.37.16","1.37.14","version_33","1.37.15","1.37.13","version_32","1.37.12","1.37.11","1.37.10","version_31","version_30","1.37.9","1.37.8","1.37.7","1.37.6","1.37.5","1.37.4","version_29","version_28","1.37.3","version_27","version_26","1.37.2","version_25","version_24","version_23","version_22","version_21","1.37.1","1.37.0","version_20","version_19","version_18","1.36.14","version_17","1.36.13","version_16","1.36.12","version_15","version_14","version_13","1.36.11","1.36.10","version_12","version_11","1.36.9","1.36.8","1.36.7","1.36.6","version_10","version_9","1.36.5","1.36.4","version_8","binary_0xb","version_3","version_7","1.36.3","1.36.2","version_6","version_5","version_4","version_2","version_1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14957.json","vanir_signatures_modified":"2026-08-12T15:13:42Z","vanir_signatures":[{"target":{"file":"src/wasm/wasm-ir-builder.cpp","function":"IRBuilder::makeLocalGet"},"deprecated":false,"digest":{"function_hash":"37150401213921437638495408923897731541","length":231},"id":"CVE-2025-14957-05b5addf","signature_type":"Function","signature_version":"v1","source":"https://github.com/webassembly/binaryen/commit/6fb2b917a79578ab44cf3b900a6da4c27251e0d4"},{"signature_version":"v1","source":"https://github.com/webassembly/binaryen/commit/6fb2b917a79578ab44cf3b900a6da4c27251e0d4","target":{"file":"src/wasm/wasm-ir-builder.cpp"},"deprecated":false,"digest":{"line_hashes":["65441754353024101277539308434159489327","207873389646354154682199852490523773173","219349994740340068868696286143452017109","166706870223361901880824879789026356755","232751961893424969708494111437530940202","141402255153278176322461148032485203893","74260984435590539904607112954906817945","66222039135351211860914597854891841928","209497641050048235992456462459555589116","318822604100098903653366680634304782248","302096927631525680812671872706320625246","66222039135351211860914597854891841928"],"threshold":0.9},"id":"CVE-2025-14957-9724968f","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"289982815675862881458904321668324794935","length":280},"id":"CVE-2025-14957-9efbc9e0","signature_type":"Function","signature_version":"v1","source":"https://github.com/webassembly/binaryen/commit/6fb2b917a79578ab44cf3b900a6da4c27251e0d4","target":{"file":"src/wasm/wasm-ir-builder.cpp","function":"IRBuilder::makeLocalSet"}},{"id":"CVE-2025-14957-f6e01615","signature_type":"Function","signature_version":"v1","source":"https://github.com/webassembly/binaryen/commit/6fb2b917a79578ab44cf3b900a6da4c27251e0d4","target":{"file":"src/wasm/wasm-ir-builder.cpp","function":"IRBuilder::makeLocalTee"},"deprecated":false,"digest":{"function_hash":"282749212566432830466598371267514264991","length":313}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}