A NULL pointer dereference was discovered in SExpressionWasmBuilder::makeBlock in wasm/wasm-s-parser.c in Binaryen 1.38.26. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-as.
{ "binaries": [ { "binary_name": "binaryen", "binary_version": "91-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-18378.json"
{ "binaries": [ { "binary_name": "binaryen", "binary_version": "105-1" } ] }
{ "binaries": [ { "binary_name": "binaryen", "binary_version": "108-1" } ] }
{ "binaries": [ { "binary_name": "binaryen", "binary_version": "120-4" } ] }