CVE-2025-6275: WebAssembly wabt binary-reader-interp.cc GetFuncOffset use after free
A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-interp.cc. The manipulation leads to use after free. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. A similar issue reported during the same timeframe was disputed by the code maintainer because it might not affect "real world wasm programs". Therefore, this entry might get disputed as well in the future.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6275?
CVE-2025-6275 is classified as a problematic vulnerability due to its potential for exploitation leading to use after free issues.
How do I fix CVE-2025-6275?
To fix CVE-2025-6275, update WebAssembly wabt to version 1.0.38 or later.
What component of WebAssembly wabt is affected by CVE-2025-6275?
The function GetFuncOffset in the file src/interp/binary-reader-interp.cc is affected by CVE-2025-6275.
What type of vulnerability is CVE-2025-6275?
CVE-2025-6275 is a use after free vulnerability affecting WebAssembly wabt.
Which versions of WebAssembly wabt are impacted by CVE-2025-6275?
WebAssembly wabt versions up to and including 1.0.37 are impacted by CVE-2025-6275.