PT-2026-31685 · Bytecode Alliance · Wasmtime

CVE-2026-34944

·

Published

2026-04-09

·

Updated

2026-08-21

CVSS v3.1

5.7

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wasmtime versions prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1
Description Wasmtime, a runtime for WebAssembly, may experience an uncaught segfault on x86-64 platforms with SSE3 disabled when compiling the f64x2.splat WebAssembly instruction with Cranelift. This occurs when signals-based-traps are disabled, potentially leading to a denial-of-service condition. The issue involves loading 8 more bytes than necessary, which can result in loading from unmapped guard pages. While the loaded data is not directly visible to WebAssembly guests, disabling signals-based-traps and enabling guard pages can cause the host process to terminate.
Recommendations Update to Wasmtime version 24.0.7, 36.0.7, 42.0.2, or 43.0.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34944
GHSA-QQFJ-4VCM-26HV
JLSEC-2026-1357
OPENSUSE-SU-2026:20749-1
RUSTSEC-2026-0087
SUSE-SU-2026:21789-1

Affected Products

Wasmtime