cranelift-codegen
crates.io7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting cranelift-codegenpage 1 of 1
- CVE-2021-32629HIGHCVSS 7.2EG 7.2✓ Fixed in 0.73.12021-05-24
Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a …
- CVE-2022-23636MEDIUMCVSS 5.1EG 5.1✓ Fixed in 0.85.22022-02-16
Wasmtime is an open source runtime for WebAssembly & WASI. Prior to versions 0.34.1 and 0.33.1, there exists a bug in the pooling instance allocator in Wasmtime's runtime where a failure to instantiate an instance for a module that defines…
- CVE-2022-31104MEDIUMCVSS 4.8EG 4.8✓ Fixed in 0.85.12022-06-28
Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal for WebAssembly on x86_64 contained two distinct bugs in the instruction lowerings implemented in Cranelift. The aarch64 …
- CVE-2022-31146MEDIUMCVSS 6.4EG 6.4✓ Fixed in 0.85.22022-07-21
Wasmtime is a standalone runtime for WebAssembly. There is a bug in the Wasmtime's code generator, Cranelift, where functions using reference types may be incorrectly missing metadata required for runtime garbage collection. This means tha…
- CVE-2022-31169MEDIUMCVSS 5.9EG 5.9✓ Fixed in 0.85.22022-07-22
Wasmtime is a standalone runtime for WebAssembly. There is a bug in Wasmtime's code generator, Cranelift, for AArch64 targets where constant divisors can result in incorrect division results at runtime. This affects Wasmtime prior to versi…
- CVE-2023-26489CRITICALCVSS 9.9EG 9.9✓ Fixed in 0.93.12023-03-08
wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of W…
- CVE-2023-27477LOWCVSS 3.1EG 3.1✓ Fixed in 0.93.12023-03-08
wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand i…
Check whether cranelift-codegen is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for cranelift-codegen CVEs against the assets you own.
Start Free Scan →