Executive brief
pywasm3 is a Python wrapper for Wasm3, a fast WebAssembly interpreter used to run portable code across different platforms. A memory management flaw allows a specially crafted WebAssembly file to crash the application or potentially execute unauthorized code. This could lead to a complete loss of system confidentiality and availability if an attacker can convince a user or automated process to load a malicious file.
Technical details
A use-after-free (UAF) vulnerability exists in the ForEachModule function within m3_env.c of the Wasm3 interpreter (and its Python binding pywasm3). The flaw is triggered during module cleanup or when handling function signature mismatches, where the runtime attempts to access memory associated with a module that has already been freed. An attacker can exploit this by providing a malformed WebAssembly (.wasm) file. Successful exploitation can lead to arbitrary code execution or a denial-of-service (DoS) condition. The vulnerability was identified in commit 139076a and affects pywasm3 versions up to 0.5.0. No official patch was confirmed at the time of the advisory.
Affected products
- wasm3 pywasm3 <= 0.5.0
- wasm3 wasm3 139076a
Timeline
- 2024-02-05: disclosed: Issue reported on GitHub repository
- 2024-11-08: advisory: NVD published CVE-2024-27530
- 2024-11-09: advisory: GitHub Advisory GHSA-46r6-92jg-22jg published