Vulnerabilities > CVE-2023-52284 - Double Free vulnerability in Bytecodealliance Webassembly Micro Runtime

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
bytecodealliance
CWE-415

Summary

Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.

Common Weakness Enumeration (CWE)