GHSA-rrmw-gv85-w824LowCVSS 3.3
pywasm3 has Improper Restriction of Operations within the Bounds of a Memory Buffer
🔗 CVE IDs covered (1)
📋 Description
A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-of-bounds write. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
🎯 Affected products1
- pip/pywasm3:<= 0.5.0
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2025-6272
- https://github.com/wasm3/wasm3/issues/531
- https://github.com/user-attachments/files/19516600/wasm3_crash.txt
- https://vuldb.com/?ctiid.313276
- https://vuldb.com/?id.313276
- https://vuldb.com/?submit.593008
- https://github.com/pypa/advisory-database/tree/main/vulns/pywasm3/PYSEC-2025-186.yaml
- https://github.com/wasm3/pywasm3/blob/main/wasm3/m3_compile.c#L333
- https://github.com/advisories/GHSA-rrmw-gv85-w824