Skip to content

RUSTSEC-2026-0096: Miscompiled guest heap access enables sandbox escape on aarch64 Cranelift #404

@github-actions

Description

@github-actions
Details
Package wasmtime
Version 40.0.4
URL GHSA-jhxm-h53p-jm7w
Patched Versions >=36.0.7, <37.0.0 OR >=42.0.2, <43.0.0 OR >=43.0.1
Aliases CVE-2026-34971, GHSA-jhxm-h53p-jm7w

This is an entry in the RustSec database for the Wasmtime security advisory
located at
GHSA-jhxm-h53p-jm7w
For more information see the GitHub-hosted security advisory.

Metadata

Metadata

Assignees

No one assigned

    Labels

    BotIssue is from a botyaraxIssue related to Yara-X

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions