Vulnerability Description
A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/interp/binary-reader-interp.cc. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webassembly | Wabt | 1.0.36 |
Related Weaknesses (CWE)
References
- https://github.com/WebAssembly/wabt/issues/2557ExploitIssue Tracking
- https://github.com/WebAssembly/wabt/issues/2557#issue-2900405517ExploitIssue Tracking
- https://vuldb.com/?ctiid.300544Permissions RequiredVDB Entry
- https://vuldb.com/?id.300544Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.515406Third Party AdvisoryVDB Entry
FAQ
What is CVE-2025-2584?
CVE-2025-2584 is a vulnerability with a CVSS score of 5.0 (MEDIUM). A vulnerability was found in WebAssembly wabt 1.0.36. It has been declared as critical. This vulnerability affects the function BinaryReaderInterp::GetReturnCallDropKeepCount of the file wabt/src/inte...
How severe is CVE-2025-2584?
CVE-2025-2584 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2584?
Check the references section above for vendor advisories and patch information. Affected products include: Webassembly Wabt.