alexcrichton opened PR #14484 from alexcrichton:guard-cap to bytecodealliance:main:
This commit adds a defense-in-depth assertion to the generation of entry trampolines into WebAssembly that the size of the stack buffer passed in is sufficient. This should never actually be hit at runtime because dynamically the stack buffer should always be of an appropriate size, but the consequences for getting this wrong are pretty catastrophic. As an entry trampoline compare-and-branch the cost is expected to be worth it.
part of https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-32h6-97mm-8q3c
<!--
Please make sure you include the following information:
If this work has been discussed elsewhere, please include a link to that
conversation. If it was discussed in an issue, just mention "issue #...".Explain why this change is needed. If the details are in an issue already,
this can be brief.Our development process is documented in the Wasmtime book:
https://docs.wasmtime.dev/contributing-development-process.htmlPlease review the Bytecode Alliance's AI tool usage policy at
https://github.com/bytecodealliance/governance/blob/main/AI_TOOL_POLICY.mdPlease ensure all communication follows the code of conduct:
https://github.com/bytecodealliance/wasmtime/blob/main/CODE_OF_CONDUCT.md
-->
alexcrichton requested cfallin for a review on PR #14484.
alexcrichton requested wasmtime-compiler-reviewers for a review on PR #14484.
alexcrichton requested wasmtime-core-reviewers for a review on PR #14484.
alexcrichton has enabled auto merge for PR #14484.
:thumbs_up: adamrk submitted PR review.
alexcrichton added PR #14484 Trap in wasm entry trampolines if the buffer is too small to the merge queue.
:check: alexcrichton merged PR #14484.
alexcrichton removed PR #14484 Trap in wasm entry trampolines if the buffer is too small from the merge queue.
Last updated: Oct 11 2026 at 04:10 UTC