Vulnerability Description
WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has been patched in version 2.4.4.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bytecodealliance | Webassembly Micro Runtime | < 2.4.4 |
Related Weaknesses (CWE)
References
- https://github.com/bytecodealliance/wasm-micro-runtime/releases/tag/WAMR-2.4.4Release Notes
- https://github.com/bytecodealliance/wasm-micro-runtime/security/advisories/GHSA-ExploitVendor Advisory
- https://github.com/bytecodealliance/wasm-micro-runtime/security/advisories/GHSA-ExploitVendor Advisory
FAQ
What is CVE-2025-64704?
CVE-2025-64704 is a vulnerability with a CVSS score of 4.7 (MEDIUM). WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is susceptible to a segmentation fault in v128.store instruction. This issue has b...
How severe is CVE-2025-64704?
CVE-2025-64704 has been rated MEDIUM with a CVSS base score of 4.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-64704?
Check the references section above for vendor advisories and patch information. Affected products include: Bytecodealliance Webassembly Micro Runtime.