Bug 2468983 (CVE-2026-8257) - CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulation in IRBuilder::makeBrOn
Summary: CVE-2026-8257 binaryen: WebAssembly Binaryen: Denial of Service via manipulat...
Keywords:
Status: NEW
Alias: CVE-2026-8257
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2469049
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-11 02:01 UTC by OSIDB Bzimport
Modified: 2026-05-11 13:34 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-11 02:01:21 UTC
A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of the file src/wasm/wasm-ir-builder.cpp of the component BrOn Parser. Performing a manipulation results in reachable assertion. The attack needs to be approached locally. The exploit is now public and may be used. The patch is named 1251efbc1ea471c1311d2726b2bbe061ff2a291c. It is suggested to install a patch to address this issue.


Note You need to log in before you can comment on or make changes to this bug.