DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-104855: CVE-2026-104855: Sandbox Escape via Reentrant State Desynchronization in Wasmtime Bulk Memory Operations

CVE-2026-104855: Sandbox Escape via Reentrant State Desynchronization in Wasmtime Bulk Memory Operations

Vulnerability ID: CVE-2026-104855
CVSS Score: 2.0
Published: 2026-10-02

CVE-2026-104855 is a critical vulnerability involving a race condition and reentrant state desynchronization within Wasmtime, a standalone WebAssembly runtime. Due to incremental mid-operation preemption points in compiler-generated loops for bulk memory and table operations, a host-defined epoch or fuel deadline callback could mutate the WebAssembly Store. Upon resuming, the virtual machine utilized stale cached pointers, resulting in use-after-free, out-of-bounds writes, and sandbox escape.

TL;DR

A state desynchronization flaw in Wasmtime's bulk operations allowed host reentrancy during loop preemption checks. Under specific configurations, a callback could modify the linear memory layout or garbage-collection heap, causing the resumed loop to perform use-after-free operations or out-of-bounds writes, potentially leading to WebAssembly sandbox escape.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization)
  • Attack Vector: Network / Local
  • CVSS Score: 2.0 (Low Base / Critical Downstream Impact)
  • EPSS Score: Not Listed
  • Impact: Sandbox Escape, Memory Corruption (Use-After-Free, Out-of-Bounds Write)
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Wasmtime standalone WebAssembly runtime
  • Wasmtime: >= 46.0.0, < 46.0.2 (Fixed in: 46.0.2)
  • Wasmtime: >= 47.0.0, < 47.0.3 (Fixed in: 47.0.3)

Code Analysis

Commit: 3ebfbe5

Wasmtime Atomic Operation Commit (PR #14045)

Commit: 99b0bc3

Wasmtime Main Fix Commit (v47.0.3)

Commit: a3eb27a

Wasmtime Patch Commit (v46.0.2)

Mitigation Strategies

  • Upgrade to Wasmtime 46.0.2, 47.0.3, or later versions.
  • Avoid mutating critical Store resources (such as growing memory or tables) within user-defined host epoch or fuel deadline callbacks.
  • Implement resource limiters to prevent guest modules from performing excessively large, non-preemptible bulk memory copies that could lead to CPU thread starvation.

Remediation Steps:

  1. Update cargo.toml dependencies for bytecodealliance/wasmtime to at least 46.0.2 or 47.0.3.
  2. Run cargo update in the project root to fetch the updated crate version.
  3. Audit all registered epoch_deadline_callback and set_fuel callback implementations for potential reentrant mutations to the store state.

References


Read the full report for CVE-2026-104855 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)