Executive brief
Wasmtime is a WebAssembly runtime that executes untrusted code. A flaw in its WASI (WebAssembly System Interface) file descriptor handling allows malicious code to repeatedly renumber file descriptors without properly cleaning up host resources, causing the host process to exhaust available file descriptors and system memory. Affected hosts must run untrusted WebAssembly code with file I/O permissions to be vulnerable.
Technical details
Wasmtime's native implementation of WASIp1 contains a resource leak in the `fd_renumber` function (CWE-400: Uncontrolled Resource Consumption). When a WebAssembly guest renames a file descriptor, the implementation updates only the guest-side descriptor table while failing to clean up the underlying host file descriptor. Over repeated calls in a loop, a malicious guest can exhaust host file descriptors and other resources without triggering cleanup until the entire Store is destroyed. The vulnerability requires three conditions: the host must load and execute a WebAssembly core module exposing `fd_renumber`, expose the ability to acquire file descriptors (e.g., file open), and allow untrusted guest code execution. Patches are available in Wasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2.
Affected products
- Bytecode Alliance wasmtime-wasi < 24.0.10, >= 25.0.0 and < 36.0.11, >= 37.0.0 and < 44.0.3, >= 45.0.0 and < 45.0.2
Timeline
- 2026-06-15: disclosed: GHSA advisory published
- 2026-06-15: patched: Wasmtime 24.0.10, 36.0.11, 44.0.3, and 45.0.2 released with fix
- 2026-08-26: advisory: GitHub Advisory Database updated