CVE-2024-34250

Publication date 6 May 2024

Last updated 4 February 2025


Ubuntu priority

A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c.

Read the notes from the security team

Status

Package Ubuntu Release Status
netdata 24.10 oracular
Fixed 1.44.3-2ubuntu0.1
24.04 LTS noble
Not affected
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected

Notes


rodrigo-zaiden

netdata embeds wasm-micro-runtime code.

References

Related Ubuntu Security Notices (USN)

    • USN-7250-1
    • Netdata vulnerabilities
    • 3 February 2025

Other references