CVE-2025-6272

A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-of-bounds write. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/user-attachments/files/19516600/wasm3_crash.txt Exploit
https://github.com/wasm3/wasm3/issues/531 Exploit Issue Tracking
https://vuldb.com/?ctiid.313276 Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?id.313276 Third Party Advisory VDB Entry
https://vuldb.com/?submit.593008 Third Party Advisory VDB Entry
https://github.com/wasm3/wasm3/issues/531 Exploit Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:wasm3_project:wasm3:0.5.0:*:*:*:*:*:*:*

History

02 Jul 2025, 19:04

Type Values Removed Values Added
References () https://github.com/user-attachments/files/19516600/wasm3_crash.txt - () https://github.com/user-attachments/files/19516600/wasm3_crash.txt - Exploit
References () https://github.com/wasm3/wasm3/issues/531 - () https://github.com/wasm3/wasm3/issues/531 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.313276 - () https://vuldb.com/?ctiid.313276 - Permissions Required, Third Party Advisory, VDB Entry
References () https://vuldb.com/?id.313276 - () https://vuldb.com/?id.313276 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.593008 - () https://vuldb.com/?submit.593008 - Third Party Advisory, VDB Entry
CPE cpe:2.3:a:wasm3_project:wasm3:0.5.0:*:*:*:*:*:*:*
First Time Wasm3 Project
Wasm3 Project wasm3

23 Jun 2025, 20:16

Type Values Removed Values Added
References () https://github.com/wasm3/wasm3/issues/531 - () https://github.com/wasm3/wasm3/issues/531 -
Summary
  • (es) Se ha detectado una vulnerabilidad en wasm3 0.5.0, clasificada como problemática. Esta vulnerabilidad afecta a la función MarkSlotAllocated del archivo source/m3_compile.c. La manipulación provoca escritura fuera de los límites. Un ataque debe abordarse localmente. Se ha hecho público el exploit y puede que sea utilizado.

19 Jun 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-19 18:15

Updated : 2025-07-02 19:04


NVD link : CVE-2025-6272

Mitre link : CVE-2025-6272

CVE.ORG link : CVE-2025-6272


JSON object : View

Products Affected

wasm3_project

  • wasm3
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-787

Out-of-bounds Write