← Vulnerability feed

Vulnerability record · CVE-2023-27477 · published 8 March 2023

CVE-2023-27477: Bytecodealliance cranelift-codegen vulnerability

Bytecodealliance · Cranelift Codegen

wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than 16. There is an off-by-one error in the calculation of the mask to the `pshufb` instruction which causes incorrect results to be returned if lanes are selected from the second vector. This codegen bug has been fixed in Wasmtiem 6.0.1, 5.0.1, and 4.0.1. Users are recommended to upgrade to these updated versions. If upgrading is not an option for you at this time, you can avoid this miscompilation by disabling the Wasm simd proposal. Additionally the bug is only present on x86_64 hosts. Other platforms such as AArch64 and s390x are not affected.

4.3 CVSS 3.1 Medium EPSS 0.62% · top 52.2% CWE-193 · CWE-193
4.3CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's code generation backend, Cranelift, has a bug on x86_64 platforms for the WebAssembly `i8x16.select` instruction which will produce the wrong results when the same operand is provided to the instruction and some of the selected indices are greater than 16. There is an off-by-one error in the calculation of the mask to the `pshufb` instruction which causes incorrect results to be returned if lanes are selected from the second vector. This codegen bug has been fixed in Wasmtiem 6.0.1, 5.0.1, and 4.0.1. Users are recommended to upgrade to these updated versions. If upgrading is not an option for you at this time, you can avoid this miscompilation by disabling the Wasm simd proposal. Additionally the bug is only present on x86_64 hosts. Other platforms such as AArch64 and s390x are not affected.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27477 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2023-26489Bytecodealliance cranelift-codegen out-of-bounds read vulnerabilitywasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where a…EPSS 1.3%9.8CVE-2022-39394Bytecodealliance wasmtime out-of-bounds write vulnerabilityWasmtime is a standalone runtime for WebAssembly. Prior to version 2.0.2, there is a bug in Wasmtime's C API implementation where the definition of t…EPSS 0.34%9.8CVE-2022-24791Bytecodealliance wasmtime use after free vulnerabilityWasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wa…EPSS 1.2%9.0CVE-2026-34987Bytecodealliance wasmtime out-of-bounds read vulnerabilityWasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime with its Winch (baseline) non-default compiler back…EPSS 0.49%9.0CVE-2026-34971Bytecodealliance wasmtime out-of-bounds read vulnerabilityWasmtime is a runtime for WebAssembly. From 32.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Cranelift compilation backend contains a bug on a…EPSS 0.39%8.8CVE-2023-30624Bytecodealliance wasmtime vulnerabilityWasmtime is a standalone runtime for WebAssembly. Prior to versions 6.0.2, 7.0.1, and 8.0.1, Wasmtime's implementation of managing per-instance state…EPSS 0.45%8.8CVE-2022-31146Bytecodealliance cranelift-codegen use after free vulnerabilityWasmtime is a standalone runtime for WebAssembly. There is a bug in the Wasmtime's code generator, Cranelift, where functions using reference types m…EPSS 1.2%8.8CVE-2021-32629Bytecodealliance cranelift-codegen out-of-bounds read vulnerabilityCranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into execu…EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2023-27477), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.