cranelift-codegen
crates.io7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cranelift-codegenpage 1 of 1
- CVE-2021-32629HIGHCVSS 7.2EG 7.2fixed in 0.73.12021-05-24
Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a …
- CVE-2022-23636MEDIUMCVSS 5.1EG 5.1fixed in 0.85.22022-02-16
Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in the pooling instance allocator in Wasmtime's runtime where a failure to instantiate an instance for a module that defines…
- CVE-2022-31104MEDIUMCVSS 4.8EG 4.8fixed in 0.85.12022-06-28
Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal for WebAssembly on x86_64 contained two distinct bugs in the instruction lowerings implemented in Cranelift. The aarch64 …
- CVE-2022-31146MEDIUMCVSS 6.4EG 6.4fixed in 0.85.22022-07-21
Wasmtime is a standalone runtime for WebAssembly. There is a bug in the Wasmtime's code generator, Cranelift, where functions using reference types may be incorrectly missing metadata required for runtime garbage collection. This means tha…
- CVE-2022-31169MEDIUMCVSS 5.9EG 5.9fixed in 0.85.22022-07-22
Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 targets where constant divisors can result in incorrect division results at runtime. This affects Wasmtime prior to versi…
- CVE-2023-26489CRITICALCVSS 9.9EG 9.9fixed in 0.91.1, 0.92.1 or 0.93.1, by version range2023-03-08
wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of W…
- CVE-2023-27477LOWCVSS 3.1EG 3.1fixed in 0.91.1, 0.92.1 or 0.93.1, by version range2023-03-08
wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand i…
Check whether cranelift-codegen is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cranelift-codegen CVEs against the assets you own.
Book a Demo →