CVE-2026-34941
mediumCVSS v3 Base Score
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
None
Integrity
None
Availability
Low
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in Wasmtime, a runtime for WebAssembly. When transcoding a UTF-16 string to the latin1+utf16 component-model encoding, Wasmtime incorrectly validates the byte length of the input string, checking the number of code units instead of the actual byte length. This vulnerability can lead to a Denial of Service (DoS) by causing the host process to terminate with a segmentation fault. In nonstandard configurations where guard pages are disabled, this flaw may also allow for information disclosure by reading beyond the end of WebAssembly's linear memory.
CWE
CWE-135Affected Products
Red Hat Connectivity Link 1Red Hat Enterprise Linux 10