CVE-2023-48105: High severity bytecodealliance Webassembly Micro Runtime vulnerability
An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasmloaderpreparebytecode function in core/iwasm/interpreter/wasmloader.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-48105?
CVE-2023-48105 is a heap overflow vulnerability in the Bytecode alliance wasm-micro-runtime v.1.2.3.
How does CVE-2023-48105 impact the Bytecode alliance wasm-micro-runtime?
CVE-2023-48105 allows a remote attacker to cause a denial of service through the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.
What is the severity of CVE-2023-48105?
CVE-2023-48105 has a severity rating of 7.5 (high).
How can I fix the CVE-2023-48105 vulnerability?
To fix the CVE-2023-48105 vulnerability, update the Bytecode alliance wasm-micro-runtime to version 1.2.4 or later.
Where can I find more information about CVE-2023-48105?
You can find more information about CVE-2023-48105 on the following websites: [bytecode.com](http://bytecode.com), [wasm-micro-runtime.com](http://wasm-micro-runtime.com), and [github.com/bytecodealliance/wasm-micro-runtime/issues/2726](https://github.com/bytecodealliance/wasm-micro-runtime/issues/2726).