CVE-2022-31169 is a bug in Wasmtime's Cranelift code generator for AArch64 targets, affecting Wasmtime prior to version 0.38.2 and Cranelift prior to 0.85.2. Incorrect constant divisor handling can lead to erroneous division results at runtime, causing WebAssembly programs to deviate from specification within the sandbox. With a CVSS score of 7.5 (HIGH), this vulnerability has a network attack vector and low attack complexity, potentially leading to high integrity impact on guest programs, though not directly impacting host systems. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.85.1CPE matchmatch criteria | cpe:2.3:a:bytecodealliance:cranelift-codegen:*:*:*:*:*:rust:*:* | ||
< 0.38.1CPE matchmatch criteria | cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.