{"id":"GHSA-g4v2-cjqp-rfmq","summary":"Critical Use-After-Free in Wasmi's Linear Memory","details":"### Summary\n\nA use-after-free vulnerability has been discovered in the linear memory implementation of Wasmi. This issue can be triggered by a WebAssembly module under certain memory growth conditions, potentially leading to memory corruption, information disclosure, or code execution.\n\n### Impact\n\n- **Confidentiality:** High – attacker-controlled memory reads possible.\n- **Integrity:** High – memory corruption may allow arbitrary writes.\n- **Availability:** High – interpreter crashes possible.\n\n### Affected Versions\n\nWasmi `v0.41.0` through Wasmi `v1.0.0`.\n\n### Workarounds\n\n- Upgrade to the latest patched version of Wasmi.\n- Consider limiting the maximum linear memory sizes where feasible.\n\n### Credits\n\nThis vulnerability was discovered by **Robert T. Morris (RTM)**.","aliases":["CVE-2025-66627"],"modified":"2026-09-10T03:50:31.952950700Z","published":"2025-12-08T22:15:49Z","database_specific":{"cwe_ids":["CWE-416"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-12-08T22:15:49Z","nvd_published_at":"2025-12-09T16:18:21Z"},"references":[{"type":"WEB","url":"https://github.com/wasmi-labs/wasmi/security/advisories/GHSA-g4v2-cjqp-rfmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66627"},{"type":"WEB","url":"https://github.com/wasmi-labs/wasmi/commit/0e6f0d2a8325602c58d6a53ce1c0e6045eb6a490"},{"type":"PACKAGE","url":"https://github.com/wasmi-labs/wasmi"}],"affected":[{"package":{"name":"wasmi","ecosystem":"crates.io","purl":"pkg:cargo/wasmi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.41.0"},{"fixed":"0.41.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-g4v2-cjqp-rfmq/GHSA-g4v2-cjqp-rfmq.json"}},{"package":{"name":"wasmi","ecosystem":"crates.io","purl":"pkg:cargo/wasmi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.42.0"},{"fixed":"0.47.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-g4v2-cjqp-rfmq/GHSA-g4v2-cjqp-rfmq.json"}},{"package":{"name":"wasmi","ecosystem":"crates.io","purl":"pkg:cargo/wasmi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.50.0"},{"fixed":"0.51.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-g4v2-cjqp-rfmq/GHSA-g4v2-cjqp-rfmq.json"}},{"package":{"name":"wasmi","ecosystem":"crates.io","purl":"pkg:cargo/wasmi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"1.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-g4v2-cjqp-rfmq/GHSA-g4v2-cjqp-rfmq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}