CVE-2026-34971
bytecodealliance wasmtime, Red Hat Connectivity Link 1, Red Hat Enterprise Linux 10
Wasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on aarch64 when performing a certain shape of heap accesses which means that the wrong address is accessed. When combined with explicit bounds checks a guest WebAssembly module this can create a situation where there are two diverging computations for the same address: one for the address to bounds-check and one for the address to load. This difference in address being operated on means that a guest module can pass a bounds check but then load a di...
- CVSS
- 9
- EPSS
- 0.32% 24.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.10