#VU125758 Out-of-bounds read in Wasmtime - CVE-2026-34944
Published: April 10, 2026
Wasmtime
Bytecode Alliance
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in Cranelift's compilation of the f64x2.splat WebAssembly instruction on x86-64 when processing a memory-loaded value without SSE3. A local user can execute crafted WebAssembly that triggers the widened load to cause a denial of service.
Exploitation requires guard pages to be enabled and signals-based-traps to be disabled. User interaction is required.