CVE-2025-64345 describes an unsound interaction in Wasmtime's Rust embedder API, affecting versions prior to 38.0.4, 37.0.3, 36.0.3, and 24.0.5. This vulnerability allows for a data race in the host due to shared WebAssembly linear memory being viewed as a safe type, despite parallel modifications. With a CVSS score of 1.8 (LOW), exploitation requires high privileges and user interaction, with a local attack vector, leading to a low impact on integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bytecodealliance | Wasmtime | < 24.0.5, >= 26.0.0, < 36.0.3, >= 37.0.0, < 37.0.3, >= 38.0.1, < 38.0.4CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.