diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml --- a/security/vuxml/vuln/2026.xml +++ b/security/vuxml/vuln/2026.xml @@ -1,3 +1,48 @@ + + tree-sitter-cli -- Always-Incorrect Control Flow Implementation in wasmtime crate + + + tree-sitter-cli + 0.26.9 + + + + +

https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-q49f-xg75-m9xw reports:

+
+

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, +42.0.2, and 43.0.1, Wasmtime's Winch compiler contains a vulnerability +where the compilation of the table.fill instruction can result in +a host panic. This means that a valid guest can be compiled with +Winch, on any architecture, and cause the host to panic. This +represents a denial-of-service vulnerability in Wasmtime due to +guests being able to trigger a panic. The specific issue is that +a historical refactoring changed how compiled code referenced tables +within the table.* instructions. This refactoring forgot to update +the Winch code paths associated as well, meaning that Winch was +using the wrong indexing scheme. Due to the feature support of +Winch the only problem that can result is tables being mixed up or +nonexistent tables being used, meaning that the guest is limited +to panicking the host (using a nonexistent table), or executing +spec-incorrect behavior and modifying the wrong table. This +vulnerability is fixed in crate versions: 36.0.7, 42.0.2, and 43.0.1.

+
+ +
+ + RUSTSEC-2026-0089 + https://rustsec.org/advisories/RUSTSEC-2026-0089 + CVE-2026-34946 + https://cveawg.mitre.org/api/cve/CVE-2026-34946 + GHSA-q49f-xg75-m9xw + https://github.com/advisories/GHSA-q49f-xg75-m9xw + + + 2026-04-09 + 2026-06-08 + +
+ OpenSSL -- Multiple vulnerabilities