The vendor explicitly identifies these products as affected by this CVE.
- openshift/ose-rhel-coreos-9 as a component of Red Hat OpenShift Container Platform 4
- wasmedge as a component of Red Hat OpenShift Container Platform 4
- wasmedge-devel as a component of Red Hat OpenShift Container Platform 4
- wasmedge-rt as a component of Red Hat OpenShift Container Platform 4
- wasmedge.src as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in WasmEdge, a WebAssembly runtime. A multiplication error within the `checkAccessBound()` function can lead to incorrect memory access. This vulnerability allows a remote attacker to trigger a segmentation fault, causing the program to crash and resulting in a Denial of Service (DoS).
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
