CVE-2025-3122 LOW

CVE-2025-3122: WebAssembly wabt binary-reader-interp.cc BeginFunctionBody null pointer dereference

Vendor Webassembly
Product wabt
Weakness CWE-476
Published April 2, 2025
Last update April 3, 2025

CVSS base score

2.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

Key dates

02Disclosure timeline

April 2, 2025 CVE published
April 3, 2025 Record updated