pchickey opened PR #14403 from pchickey:fix_ghsa_j2g9_main to bytecodealliance:main:
<!--
Please make sure you include the following information:
If this work has been discussed elsewhere, please include a link to that
conversation. If it was discussed in an issue, just mention "issue #...".Explain why this change is needed. If the details are in an issue already,
this can be brief.Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.htmlPlease review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.mdPlease ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->
pchickey requested rvolosatovs for a review on PR #14403.
pchickey requested wasmtime-wasi-reviewers for a review on PR #14403.
pchickey requested dicej for a review on PR #14403.
pchickey requested wasmtime-core-reviewers for a review on PR #14403.
pchickey requested alexcrichton for a review on PR #14403.
pchickey edited PR #14403:
Replaces #14397
<!--
Please make sure you include the following information:
If this work has been discussed elsewhere, please include a link to that
conversation. If it was discussed in an issue, just mention "issue #...".Explain why this change is needed. If the details are in an issue already,
this can be brief.Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.htmlPlease review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.mdPlease ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->
pchickey edited PR #14403:
Replaces #14397
<!--
Please make sure you include the following information:
If this work has been discussed elsewhere, please include a link to that
conversation. If it was discussed in an issue, just mention "issue #...".Explain why this change is needed. If the details are in an issue already,
this can be brief.Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.htmlPlease review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.mdPlease ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->
:thumbs_up: dicej submitted PR review.
pchickey edited PR #14403:
Replaces #14397
Tracking as security issue https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-j2g9-4prp-pf6h
The wasmtime-wasi crate allows guest WASI programs to trigger a host panic by specifying a filesystem timestamp value where the microseconds field overflows the seconds field. The root of the issue is that
std::time::Duration::newpanics in this case, rather than return an error.This PR fixes the issues in the wasip2 and wasip3 host implementations by first adding the microseconds field to the seconds field with the appropriate overflow checks before calling Duration::new. Tests are added for the wasip2 and p3 paths. Since p1 is implemented straightforwardly in terms of p2, there are no additional tests added to exercise the p1 path.
wasip1
The
path_filestat_set_timesandfd_filestat_set_timesfunctions take atimestamptyped argumentsatimandmtim. A host panic is exposed if the microseconds can overflow the seconds field of this struct, e.g.Timestamp { seconds: u64::MAX, microseconds: 1_000_000_000 }, when passed in either argument position (atim or mtim) to these functions, as long as fst_flags does not obviate the atim or mtim argument with the ATIM_NOW/MTIM_NOW flag.wasip2
The
set-timesandset-times-atmethods onwasi:filesystem/types.descriptortake twonew-timestamptyped argumentsatimandmtimwhere thetimestampvariant takes adatetimestruct. A host panic is exposed if the microseconds can overflow the seconds field of this struct, e.g.NewTimestamp::Timestamp(Datetime { seconds: u64::MAX, microseconds: 1_000_000_000 }), when passed in either argument position (atim or mtim) to these functions.wasip3
The
set-timesandset-times-atmethods onwasi:filesystem/types.descriptortake twonew-timestamptyped argumentsatimandmtimwhere thetimestampvariant takes adatetimestruct. A host panic is exposed if the microseconds can overflow the seconds field of this struct, e.g.NewTimestamp::Timestamp(Datetime { seconds: i64::MAX, microseconds: 1_000_000_000 }), when passed in either argument position (atim or mtim) to these functions.
pchickey added PR #14403 add tests and fixes for wasi filesystem datetime overflow to the merge queue.
:check: pchickey merged PR #14403.
pchickey removed PR #14403 add tests and fixes for wasi filesystem datetime overflow from the merge queue.
Last updated: Oct 11 2026 at 04:10 UTC