Improper Check for Unusual or Exceptional Conditions in Wasmtime - #VU153230
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an improper check for unusual or exceptional conditions in the WASIp3 filesystem timestamp conversion in wasmtime-wasi on Unix hosts when processing a guest-supplied timestamp before the Unix epoch. A remote attacker can specify a pre-epoch filesystem timestamp through the WASIp3 set-times or set-times-at methods to cause a denial of service.
Only WASIp3 configurations on Unix that provide the guest with a mutable preopened descriptor are affected.