WebAssembly / WebAssembly/wabt
wasm-decompile: Assertion `false' failed.
Open
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 8.1k
- Forks
- 827
- Avg merge
- 4d 6h
- Merged PRs (30d)
- 18
Description
Environments
OS : Ubuntu 18.04 5.4.0-150-generic
Commit : e97d53c5fcbb604fc36432df4fc117d13558d7fd
Version : 1.0.34
Vulnerability Description
Affected Tool : wasm-decompile
Affected Version : <= 1.0.34
Impact : Denial of Service
- The assertion 'false' in /src/decompiler.cc:414( in wabt 1.0.34 can cause a denial of service(assertion failure) via a crafted wasm file.
case NodeType::Uninitialized:
assert(false);
break;
PoC
1. Input File
2. Reproduce
$ ~/wabt/bin/wasm-decompile wasm-decompile-PoC
3. Stack Trace
$ ~/wabt/bin/wasm-decompile wasm-decompile-PoC
wasm-decompile: ../../../../src/decompiler.cc:414: wabt::Decompiler::Value wabt::Decompiler::DecompileExpr(const wabt::Node &, const wabt::Node *): Assertion `false' failed.
Aborted
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in src/decompiler.cc:414 and inspect Decompiler::DecompileExpr around the NodeType::Uninitialized case. Reproduce the failure with the linked wasm-decompile PoC and the command shown in the issue. Done means wasm-decompile no longer aborts with an assertion for that crafted input.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp, wasm
- Domain
- compilers, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100