<Vulnerability name="CVE-2026-58494">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-07-08T20:22:16</PublicDate>
    <Bugzilla id="2498250" url="https://bugzilla.redhat.com/show_bug.cgi?id=2498250" xml:lang="en:us">
wasmtime: Wasmtime: Overwrite host files via insufficient permission checks in wasmtime-wasi
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-280</CWE>
    <Details xml:lang="en:us" source="Mitre">
Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation and renaming check directory permissions but not matching FilePerms on source and destination preopens, allowing a WASI guest with a read-only source file capability to overwrite host files exposed as FilePerms::READ through wasip1, wasip2, or wasip3 filesystem interfaces. This issue is fixed in versions 24.0.11, 36.0.12, 45.0.3, and 46.0.1.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Wasmtime, a runtime for WebAssembly. A WebAssembly System Interface (WASI) guest with a read-only source file capability can exploit this vulnerability. During hard-link creation and renaming operations, the system checks directory permissions but fails to match file permissions on source and destination preopens. This allows the guest to overwrite host files exposed with read permissions through WASI filesystem interfaces.
    </Details>
    <Statement xml:lang="en:us">
This Moderate-impact flaw in Wasmtime allows a malicious WebAssembly System Interface (WASI) guest to overwrite host files. By exploiting insufficient permission checks during hard-link and rename operations, a guest with read-only file capabilities can modify host files that are exposed with read permissions through WASI filesystem interfaces. This could lead to data integrity issues on the host system.
    </Statement>
    <PackageState cpe="cpe:/a:redhat:connectivity_link:1">
        <ProductName>Red Hat Connectivity Link 1</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>rhcl-1/wasm-shim-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>virt-firmware-rs</PackageName>
    </PackageState>
    <PackageState impact="moderate" cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rust</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-58494
https://nvd.nist.gov/vuln/detail/CVE-2026-58494
https://github.com/bytecodealliance/wasmtime/commit/5ddfd5f1ef28f2041fa07d237ad0336e167b0e0c
https://github.com/bytecodealliance/wasmtime/commit/7db94cdcf0c79cb3dfde884b534b653f2dd83367
https://github.com/bytecodealliance/wasmtime/commit/8a250aac0962ca1364b5f16525720e9d0b39edcd
https://github.com/bytecodealliance/wasmtime/commit/d3ceb56ec35f39e02496eeb4e2d9c7f4fb964d9e
https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.11
https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.12
https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.3
https://github.com/bytecodealliance/wasmtime/releases/tag/v46.0.1
https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-4ch3-9j33-3pmj
    </References>
</Vulnerability>