CVE-2026-104855: Sandbox Escape via Reentrant State Desynchronization in Wasmtime Bulk Memory Operations
Vulnerability ID: CVE-2026-104855
CVSS Score: 2.0
Published: 2026-10-02
CVE-2026-104855 is a critical vulnerability involving a race condition and reentrant state desynchronization within Wasmtime, a standalone WebAssembly runtime. Due to incremental mid-operation preemption points in compiler-generated loops for bulk memory and table operations, a host-defined epoch or fuel deadline callback could mutate the WebAssembly Store. Upon resuming, the virtual machine utilized stale cached pointers, resulting in use-after-free, out-of-bounds writes, and sandbox escape.
TL;DR
A state desynchronization flaw in Wasmtime's bulk operations allowed host reentrancy during loop preemption checks. Under specific configurations, a callback could modify the linear memory layout or garbage-collection heap, causing the resumed loop to perform use-after-free operations or out-of-bounds writes, potentially leading to WebAssembly sandbox escape.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization)
- Attack Vector: Network / Local
- CVSS Score: 2.0 (Low Base / Critical Downstream Impact)
- EPSS Score: Not Listed
- Impact: Sandbox Escape, Memory Corruption (Use-After-Free, Out-of-Bounds Write)
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- Wasmtime standalone WebAssembly runtime
-
Wasmtime: >= 46.0.0, < 46.0.2 (Fixed in:
46.0.2) -
Wasmtime: >= 47.0.0, < 47.0.3 (Fixed in:
47.0.3)
Code Analysis
Commit: 3ebfbe5
Wasmtime Atomic Operation Commit (PR #14045)
Commit: 99b0bc3
Wasmtime Main Fix Commit (v47.0.3)
Commit: a3eb27a
Wasmtime Patch Commit (v46.0.2)
Mitigation Strategies
- Upgrade to Wasmtime 46.0.2, 47.0.3, or later versions.
- Avoid mutating critical Store resources (such as growing memory or tables) within user-defined host epoch or fuel deadline callbacks.
- Implement resource limiters to prevent guest modules from performing excessively large, non-preemptible bulk memory copies that could lead to CPU thread starvation.
Remediation Steps:
- Update cargo.toml dependencies for bytecodealliance/wasmtime to at least 46.0.2 or 47.0.3.
- Run
cargo updatein the project root to fetch the updated crate version. - Audit all registered epoch_deadline_callback and set_fuel callback implementations for potential reentrant mutations to the store state.
References
Read the full report for CVE-2026-104855 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)