Hi, The following vulnerability was published for wabt. CVE-2026-90648[0]: | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in | some situations that primarily involve 32-bit platforms, aka a | "table flip" attack. It does not check the return value of calloc() | in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl- | tableops.inc). When the funcref table allocation fails, table->data | is left NULL while table->size keeps the guest-declared element | count; thus, bounds checks still pass and table element accesses | resolve to absolute memory addresses (i * | sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of | host process memory and - via table.get, table.set, and | call_indirect - arbitrary code execution, defeating the isolation | that wasm2c exists to provide (a full sandbox escape). wasm2c is | used as an in-process sandboxing boundary by RLBox and WasmBoxC, | including in Firefox, which compiles the Graphite, Hunspell, Ogg, | Expat, and Woff2 libraries via wasm2c to contain untrusted font, | media, and XML input. Therefore, sandboxing in these applications is | potentially affected. Exploitation requires the funcref table | allocation to fail, for example under an address-space limit | (RLIMIT_AS), on 32-bit hosts, with vm.overcommit_memory=2, or under | memory pressure. On 64-bit Linux with default overcommit the | allocation succeeds and the defect is not triggered. The wasm2c | memory allocator aborts on calloc failure in the same runtime; the | table allocator lacks this abort behavior. This was introduced in | commit ab9e0b55 (PR #813). If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90648 https://www.cve.org/CVERecord?id=CVE-2026-90648 [1] https://github.com/WebAssembly/wabt/issues/2831 [2] https://github.com/WebAssembly/wabt/issues/2854 [3] https://github.com/WebAssembly/wabt/commit/e197d0b7bd3fe426f5963ae540f4426a1d49e89f Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of wabt, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1150156@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <yadd@debian.org> (supplier of updated wabt package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Tue, 06 Oct 2026 21:05:12 +0200 Source: wabt Architecture: source Version: 1.0.42+dfsg+~cs1.0.39-1 Distribution: unstable Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org> Changed-By: Xavier Guimard <yadd@debian.org> Closes: 1150156 Changes: wabt (1.0.42+dfsg+~cs1.0.39-1) unstable; urgency=medium . * Team upload * New upstream version (Closes: #1150156, CVE-2026-90648) * Unfuzz patches Checksums-Sha1: eb217a7fdeef60999c9c8949deef2dbcc8278b4b 2448 wabt_1.0.42+dfsg+~cs1.0.39-1.dsc d5114dea359824409f56fa19bbabbc42e335bf70 22232 wabt_1.0.42+dfsg+~cs1.0.39.orig-node-wabt-js.tar.xz da086ad1e76486a33d7e4fb7a2c4a80fb0f3b101 649412 wabt_1.0.42+dfsg+~cs1.0.39.orig.tar.xz ee12669f6660f45f9a8a1b4f6c494b40f7a8ef7a 14888 wabt_1.0.42+dfsg+~cs1.0.39-1.debian.tar.xz Checksums-Sha256: 696f7946587b2afe76dec9741260bd02bb81f179021ae6c67eb183d4da2702b2 2448 wabt_1.0.42+dfsg+~cs1.0.39-1.dsc f1cebe162a004daf8d8885af84d0fd58fb43d84e0a104f06deb431c4011f7e0e 22232 wabt_1.0.42+dfsg+~cs1.0.39.orig-node-wabt-js.tar.xz 8765b8c000c13d10ad6c17687a1216d5ac320fce4ef9cc8d9c60be94680b7e4f 649412 wabt_1.0.42+dfsg+~cs1.0.39.orig.tar.xz a0bc52d1ee64a90b6c2c4fdbb6f22c3bdbc600d416ff08290ede9591088b906d 14888 wabt_1.0.42+dfsg+~cs1.0.39-1.debian.tar.xz Files: f4e30ff82e4650a4969f0bcf6c349d07 2448 devel optional wabt_1.0.42+dfsg+~cs1.0.39-1.dsc f44ed53d5e82d9e31f5766d9ee4fb589 22232 devel optional wabt_1.0.42+dfsg+~cs1.0.39.orig-node-wabt-js.tar.xz dc596867c7bac51c35c0ffa12aa3e51a 649412 devel optional wabt_1.0.42+dfsg+~cs1.0.39.orig.tar.xz 9b730c4a45cda54bd06a2c5c18359991 14888 devel optional wabt_1.0.42+dfsg+~cs1.0.39-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrFR64ACgkQ9tdMp8mZ 7unbnA/9Gi/muFRLfWV2Zv8ApWAogJOEtcwlhMFIzHJyHSiYR6Zl/dwNGRsXusNr 8eG8dXw/EyHmGgKpIGx7jvUp7cjl/Ip0LuMWKik0qNw1X9IElhXUxCdyZts3TTzr rWn2jHnvR0WN6eRod5FoVXymSkXFwlqWpY+MhSa0HkRH3DV7TeneRsnHmTUXTAof rqTWBS4rQt6S/sZWc224RcXn/pnSIVAmZY+Mv/l4WCt/ZWFz3H/tPpePkJxQYfna R9WjBbnJjmeW+kX6l94Csb/3jqh+9fmzxi0cDsTs75vc86/sPTOR1GK71S82oqFP oEeR4lu53SF93mnif1RGMF8M8zQ7w3xY/FAs8cAJ1DooElkruSxKKSLHfchExaVt 1YfsxauKHR2x+7enGleoJgEMyGpSdPP7OXHzyEnWkRp4fvQSMFgR0sHvJdjQ6oHv br4HTJ/BfkKwckSkjqNqdt40LP5jE+nigbl8PzHDls351NE9gf/exxN1r2IVAHHh heaOs3406qsDZ4iDDjWxbqyb45YMcyP3XFddWBkra4ZikHKxn8EiEKanGjE2Z6F6 ia8EIvpNgKjVv2HwkOdv6nQhq1N3o1FPBvUFpLQWLiTQbrfKsTuNl9cHVn9dvb2J tUJgi0nIE3zv4BPoDxoeEeV6fB+xNAmP4C9TClRsyNZhM50t0mY= =bj7u -----END PGP SIGNATURE-----
Hi Xavier, Just checked, the commit https://github.com/WebAssembly/wabt/commit/e197d0b7bd3fe426f5963ae540f4426a1d49e89f is not included in the upstream release 1.0.42. So this should not yet be closed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
wabt, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1150156@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Xavier Guimard <yadd@debian.org> (supplier of updated wabt package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 22:34:13 +0200
Source: wabt
Architecture: source
Version: 1.0.42+dfsg+~cs1.0.39-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@lists.alioth.debian.org>
Changed-By: Xavier Guimard <yadd@debian.org>
Closes: 1150156
Changes:
wabt (1.0.42+dfsg+~cs1.0.39-2) unstable; urgency=medium
.
* Team upload
* Declare compliance with policy 4.7.4
* Drop "Rules-Requires-Root: no"
* Drop "Priority: optional"
* debian/watch version 5
* Add upstream patch to fail closed when wasm2c table allocation fails
(1.0.42 did not include the fix) (Closes: #1150156, CVE-2026-90648)
Checksums-Sha1:
89d253afef5bac77b15ae9f158ac25de2e429a09 2448 wabt_1.0.42+dfsg+~cs1.0.39-2.dsc
f37d764298d972eaaf8809d2c1741315fe68b2e7 15344 wabt_1.0.42+dfsg+~cs1.0.39-2.debian.tar.xz
Checksums-Sha256:
1638d65230077f2c43283bb973bd9074f4d5dafd73320213149b4739eb78c1da 2448 wabt_1.0.42+dfsg+~cs1.0.39-2.dsc
83fe184c5b2415a78aed6986bbfd27155976e5b10bc5c3776c29a087e502efb8 15344 wabt_1.0.42+dfsg+~cs1.0.39-2.debian.tar.xz
Files:
02b40125baa0e840b07a4bd5fd5b550d 2448 devel optional wabt_1.0.42+dfsg+~cs1.0.39-2.dsc
1c95742a1e14ba4f39dd360cd864c8a5 15344 devel optional wabt_1.0.42+dfsg+~cs1.0.39-2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmrFXFoACgkQ9tdMp8mZ
7ukuNA/5AW8QQIFwPxBQSteG/r/geHJUovHkRq1b8Ww8zjPWqAayCarKj49Z0GzG
MnyVW1v65z+hyYTkpmFI7PO5kj1ONYxFlzgOsT1replZcIHXTXa1W8BMWcrU98d0
nw4Qi7lnTDwES/v/vsh5OrYcehzfTf/97pRrYT2L6S9DLhB+RqSmg9EgB25sRH2w
Auh5jZ+99WQ6gvcP8B0hbAKTgmWc03F3VB56nyCXMdU1oCRODIJZ+/NVXYY8YU41
SCLWA959URyRAT5uZnYS/21ohqGl8rIEIddTLssh5Z69K2GwsoLm899rsyqqJj7p
BozZcG8lUDcHdQ3+FSt+c36F8bqg1U1r15cGs4jdBUt1fR90vv2r3h8S5w5EyrbF
PU+49TbP2Bx851w/zyOCu9YCY7zDVbjP1ViYbPdMz+uSB7HX3MJD//JmU1Bem6CB
w6me80FYc2RNZBme/tJVy1FtfDNs/XUXDSrvsLseGxJ/UtwJ7mgDf8jsR44JdJCJ
a1BiOMW46OlaZUK7EkloxVVC2+NHCG+tbSZQNU3YQ1zV/D7Lb0pwfUdwNbzRM4aH
Md6pRHHM1jAP50YAFwyhEZmJhoyCvLs0ysCtLDxuvy49LBMFXZGBbbd0ADjR29pL
3WbrCzTdSYZsluFYb1/kM4drHrZi/ESaIDgStIuo4d+YY0xxK4U=
=s6zc
-----END PGP SIGNATURE-----