CVE-2024-34251: High severity bytecode alliance webassembly micro runtime vulnerability
Published May 6, 2024
·Updated
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "blocktypegetarity" function in core/iwasm/interpreter/wasm.h.
Affected Software
2 affected components
Bytecode Alliance wasm-micro-runtime
bytecodealliance Webassembly Micro Runtime=2.0.0
Event History
May 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 4, 2025
Data Sourced
via Ubuntu·05:08 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:12 AM
Description
Data Sourced
via Debian·05:14 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-34251?
CVE-2024-34251 is classified as a denial of service vulnerability due to an out-of-bound memory read.
2
How do I fix CVE-2024-34251?
To mitigate CVE-2024-34251, upgrade to the latest version of Bytecode Alliance wasm-micro-runtime where the vulnerability is patched.
3
What versions are affected by CVE-2024-34251?
CVE-2024-34251 affects Bytecode Alliance wasm-micro-runtime version 2.0.0.
4
What components of Bytecode Alliance wasm-micro-runtime are impacted by CVE-2024-34251?
The vulnerability specifically impacts the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
5
Can CVE-2024-34251 be exploited remotely?
Yes, CVE-2024-34251 can be exploited by a remote attacker, leading to denial of service.