Executive brief
Wasmtime is a runtime for executing WebAssembly code in a secure, isolated environment. A bug in its memory management system can allow one guest program to access the private memory of a previously running program under specific configurations. This could lead to sensitive data leakage between different users or applications sharing the same infrastructure.
Technical details
A logic error in Wasmtime's pooling allocator causes a divergence between runtime memory resetting and compile-time assumptions. Specifically, the allocator may use an incorrect predicate to determine if virtual memory permissions need to be reset when a linear memory slot is reused. If the pooling allocator is active, memory guard size is 0, and memory reservation is less than 4GiB (matching max_memory_size), the system fails to trigger a segfault on out-of-bounds loads. This allows a subsequent WebAssembly instance to read the memory remains of a previous instance. The issue is fixed in versions 36.0.7, 42.0.2, and 43.0.1.
Affected products
- Bytecode Alliance Wasmtime >= 28.0.0, < 36.0.7; >= 37.0.0, < 42.0.2; 43.0.0
Timeline
- 2026-04-09: disclosed
- 2026-04-09: advisory
- 2026-04-09: patched