{"id":"CVE-2025-69261","summary":"WasmEdge integer wrap in MemoryInstance::getSpan()'s memory size check","details":"WasmEdge is a WebAssembly runtime. Prior to version 0.16.0-alpha.3, a multiplication in `WasmEdge/include/runtime/instance/memory.h` can wrap, causing `checkAccessBound()` to incorrectly allow the access. This leads to a segmentation fault. Version 0.16.0-alpha.3 contains a patch for the issue.","aliases":["GHSA-89fm-8mr7-gg4m"],"modified":"2026-08-12T15:14:58.355769Z","published":"2025-12-30T19:43:59.746Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69261.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-190"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69261.json"},{"type":"ADVISORY","url":"https://github.com/WasmEdge/WasmEdge/security/advisories/GHSA-89fm-8mr7-gg4m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69261"},{"type":"FIX","url":"https://github.com/WasmEdge/WasmEdge/commit/37cc9fa19bd23edbbdaa9252059b17f191fa4d17"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wasmedge/wasmedge","events":[{"introduced":"0"},{"fixed":"aeea19a248a3906230018396cc398ab2493a0589"},{"fixed":"37cc9fa19bd23edbbdaa9252059b17f191fa4d17"}],"database_specific":{"cpe":"cpe:2.3:a:linuxfoundation:wasmedge:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.16.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.15.0","0.16.0-rc.1","0.16.0-alpha.4","0.16.0-alpha.3","0.16.0-alpha.2","0.16.0-alpha.1","0.15.0-rc.1","0.15.0-alpha.4","0.15.0-alpha.3","0.15.0-alpha.2","0.15.0-alpha.1","0.14.1","0.14.1-rc.5","0.14.1-rc.4","0.14.1-rc.3","0.14.1-rc.2","0.14.1-rc.1","0.14.1-beta.2","0.14.1-beta.1","0.14.0","0.14.0-rc.5","0.14.0-alpha.4","0.14.0-rc.4","0.14.0-rc.3","0.14.0-rc.2","0.14.0-rc.1","0.14.0-alpha.3","0.14.0-alpha.2","0.14.0-alpha.1","0.13.5","0.13.4","0.13.3","0.13.2","0.13.1","0.13.0","0.13.0-alpha.1","rust/0.13.1","rust-sdk/0.8.1","0.12.1","rust/0.12.0","rust-types/0.4.1","rust-sdk/0.8.0","0.12.0","0.12.0-alpha.2","0.12.0-alpha.1","rust-types/0.3.1","rust-sdk/0.7.0","rust-macro/0.3.0","rust-macro/0.2.1","rust/0.11.0","rust-sdk/0.6.0","rust-macro/0.2.0","0.11.2","0.11.2-rc.3","0.11.2-rc.2","0.11.2-rc.1","0.11.2-alpha.1","rust-sdk/0.5.0","rust/0.10.0","rust-types/0.3.0","rust-macro/0.1.0","0.11.1","0.11.1-rc.1","0.11.1-alpha.1","rust/0.9.0","rust-types/0.2.1","rust-sdk/0.4.0","0.11.0","0.11.0-rc.1","0.11.0-alpha.1","rust-sdk/0.3.0","rust/0.8.0","rust-sdk/0.2.0","rust-types/0.2.0","0.10.1","0.10.1-rc.1","0.10.1-alpha.3","0.10.1-alpha.2","0.10.1-alpha.1","0.10.0","rust-sdk/0.1.0","0.10.0-rc.1","rust/0.7.0","rust-types/0.1.3","0.10.0-alpha.2","0.10.0-alpha.1","rust-types/0.1.2","rust-types/0.1.1","rust-types/0.1.0","rust/0.5.0","rust/0.3.0","0.9.1","0.9.1-rc.1","0.9.1-beta.2","0.9.1-beta.1","0.9.1-alpha.1","0.9.0","rust/0.2.2","0.9.0-rc.5","0.9.0-rc.4","0.9.0-rc.3","rust/0.2.1","0.9.0-rc.2","0.9.0-rc.1","0.8.2","0.8.2-rc.5","0.8.2-rc.4","0.8.2-rc.3","0.8.2-rc.2","0.8.2-rc.1","0.8.1","0.8.0","0.7.3","0.6.3","0.7.2","0.7.1","0.7.0","0.6.9","0.6.8","0.6.7","0.6.6","0.6.5","0.6.4","0.6.2","0.6.1","0.6.0","0.5.1","0.5.0","0.4.0","0.3.1","0.3.0","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69261.json","vanir_signatures_modified":"2026-08-12T15:14:58Z","vanir_signatures":[{"target":{"file":"include/runtime/instance/memory.h"},"deprecated":false,"digest":{"line_hashes":["321841578989354777447708724282533735910","89818731103215995964617571996520816119","2613939707723102598886305993665912785","236303773334839303174194088992119663602","213936535720176606448703368750349849170","243716784187250461111155335855917975759","310252924324522487897276047135395880643","89108753120962946307626765540039998575","113067996317145965491398072766830351773","14580826971662117960887407870935664645"],"threshold":0.9},"id":"CVE-2025-69261-693471d6","signature_type":"Line","signature_version":"v1","source":"https://github.com/wasmedge/wasmedge/commit/37cc9fa19bd23edbbdaa9252059b17f191fa4d17"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}