Junglewise Threat Intelligence

CVE-2026-34983: Bytecode Alliance Wasmtime use-after-free in Linker cloning

CVE-2026-34983 · Severity: medium · CVSS 4 · Published 2026-04-09

Technologies: wasmtime (crates.io), wasmtime (PyPI). Vendors: crates.io, PyPI.

Executive brief

Wasmtime is a runtime for executing WebAssembly code. A technical flaw in how the software handles internal memory when copying certain components can lead to a program crash (segmentation fault). This issue only affects developers using the Wasmtime library in their own applications and does not allow external users or malicious WebAssembly programs to steal data or corrupt the system.

Technical details

A use-after-free vulnerability exists in the wasmtime crate version 43.0.0 due to an unsound implementation of the internal StringPool's cloning logic. The issue is triggered when an embedder clones a wasmtime::Linker instance, drops the original, and subsequently attempts to use the cloned instance. This occurs because the cloned linker retains references to memory owned by the original instance's interning pool. The vulnerability is not reachable by guest WebAssembly programs and typically results in a process crash (segfault) rather than heap corruption or data exfiltration. The issue was fixed in version 43.0.1 by correcting the interning pool's cloning behavior.

Affected products

  • Bytecode Alliance wasmtime 43.0.0

Timeline

  • 2026-04-09: disclosed
  • 2026-04-09: advisory
  • 2026-04-09: patched: Patched in version 43.0.1

References

Related threats