#VU127038 Always-Incorrect Control Flow Implementation in Wasmtime - CVE-2024-47763
Published: October 9, 2024 / Updated: April 23, 2026
Wasmtime
Bytecode Alliance
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of stack frames in stack-walking code when processing a WebAssembly module that combines tail calls with stack trace capture. A local user can execute a crafted WebAssembly module or component to cause a denial of service.
The issue is triggered when an exported function performs a return_call, return_call_indirect, or return_call_ref to an imported host function that captures a stack trace, such as by raising a trap.