Medium severity5.5NVD Advisory· Published Dec 31, 2023· Updated Jun 17, 2026
CVE-2023-52284
CVE-2023-52284
Description
Bytecode Alliance wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) before 1.3.0 can have an "double free or corruption" error for a valid WebAssembly module because push_pop_frame_ref_offset is mishandled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:bytecodealliance:webassembly_micro_runtime:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bytecodealliance:webassembly_micro_runtime:*:*:*:*:*:*:*:*range: <1.3.0
- (no CPE)range: <1.3.0
- Bytecode Alliance/wasm-micro-runtimedescription
- Range: <1.3.0
- Range: <1.3.0
Patches
Vulnerability mechanics
References
3- github.com/bytecodealliance/wasm-micro-runtime/compare/WAMR-1.2.3...WAMR-1.3.0nvdPatch
- github.com/bytecodealliance/wasm-micro-runtime/pull/2590nvdPatch
- github.com/bytecodealliance/wasm-micro-runtime/issues/2586nvdExploitIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.