CVE-2026-34941

medium Red Hat
CVSS v3 Base Score
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
None
Availability
Low
Published: April 9, 2026 (34 days ago)
Last Modified: April 9, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in Wasmtime, a runtime for WebAssembly. When transcoding a UTF-16 string to the latin1+utf16 component-model encoding, Wasmtime incorrectly validates the byte length of the input string, checking the number of code units instead of the actual byte length. This vulnerability can lead to a Denial of Service (DoS) by causing the host process to terminate with a segmentation fault. In nonstandard configurations where guard pages are disabled, this flaw may also allow for information disclosure by reading beyond the end of WebAssembly's linear memory.

CWE

CWE-135

Affected Products

Red Hat Connectivity Link 1Red Hat Enterprise Linux 10

References