Integer overflow in Wasmtime - #VU153030
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in wasmtime-wasi filesystem timestamp handling when processing crafted filesystem timestamp values. A remote attacker can provide a timestamp whose microseconds field overflows its seconds field to cause a denial of service.
The issue affects the WASI Preview 1, Preview 2, and Preview 3 filesystem interfaces.