First published: Tue Aug 22 2023(Updated: )
A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webassembly Binaryen | =1.38.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-18378 is a vulnerability discovered in Binaryen 1.38.26 that allows for a NULL pointer dereference in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c, leading to denial-of-service.
CVE-2020-18378 has a severity score of 6.5 (medium).
Webassembly Binaryen version 1.38.26 is affected by CVE-2020-18378.
A crafted wasm input can cause a segmentation fault, leading to denial-of-service.
To fix CVE-2020-18378, it is recommended to update to a version of Binaryen that contains the fix.