CVE-2018-16764: High severity webassembly virtual machine vulnerability
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an IR::FunctionValidationContext::catchall heap-based buffer over-read.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16764?
CVE-2018-16764 has been classified as a denial of service vulnerability due to the potential for application crashes.
How do I fix CVE-2018-16764?
To mitigate CVE-2018-16764, upgrade to a version of WebAssembly Virtual Machine released after July 26, 2018.
What types of impacts can CVE-2018-16764 have?
CVE-2018-16764 may cause application crashes and could possibly lead to other unspecified impacts.
What specific component is affected by CVE-2018-16764?
CVE-2018-16764 specifically affects the IR::FunctionValidationContext in the WebAssembly Virtual Machine.
Is CVE-2018-16764 present in all WebAssembly Virtual Machine versions?
CVE-2018-16764 is present in WebAssembly Virtual Machine versions up to and including July 26, 2018.