Use of uninitialized resource in Wasmtime - #VU153231
Published: October 3, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to use of an uninitialized resource in the WASIp1 `fd_readdir` implementation when listing entries from a preopened directory. A remote user can invoke `fd_readdir` to disclose sensitive information.
The affected guest must have access to a preopened directory, and user interaction is required.