CVE-2023-41880 is a medium-severity miscompilation vulnerability affecting Wasmtime versions 10.0.0 through 12.0.1 on x86_64 platforms. It causes the WebAssembly i64x2.shr_s instruction to produce incorrect results when the shift amount is a constant greater than 32. While not a sandbox escape, this issue can lead to incorrect program execution for affected WebAssembly modules. The vulnerability has a CVSS score of 5.3 (Medium) with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N, indicating it can be exploited remotely with low complexity, requiring no privileges or user interaction, and primarily impacting integrity. Patched versions 10.0.2, 11.0.2, and 12.0.2 resolve this issue. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. It is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0.0, < 10.0.2CPE matchmatch criteria | cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:x64:* | ||
>= 11.0.0, < 11.0.2CPE matchmatch criteria | cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:x64:* | ||
>= 12.0.0, < 12.0.2CPE matchmatch criteria | cpe:2.3:a:bytecodealliance:wasmtime:*:*:*:*:*:rust:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.