THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3p27-qvp9-27qf (low) — Wasmtime has a leak in WASIp1 `fd_renumber` implementation

[GHSA] GHSA-3p27-qvp9-27qf (low) — Wasmtime has a leak in WASIp1 `fd_renumber` implementation

medgithub_advisoriesPublished 2026-08-26

GHSA-3p27-qvp9-27qf Severity: low CVE: CVE-2026-54786

Wasmtime has a leak in WASIp1 `fd_renumber` implementation

### Impact

Wasmtime's native implementation of WASIp1 suffers from a leak in the `fd_renumber` function where the file descriptor being renumbered to is not properly closed. Wasmtime's implementation erroneously only updated the table of descriptors for WASIp1 and didn't update the u

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3p27-qvp9-27qf