LiveActive security incident?Get immediate response
CVE Record

CVE-2018-11378: The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a cra...

The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This CVE concerns radare2's WebAssembly disassembly code handling a crafted WASM file. The supplied record does not provide a CVSS score, affected versions, or a precise business impact. Treat it as a tooling risk for environments that analyze untrusted WASM, not as evidence of broad enterprise compromise.

Executive priority

Handle as a moderate operational hygiene item unless radare2 processes untrusted WASM in automated pipelines. Business urgency rises for malware analysis, CI, reverse engineering, or security tooling environments where crafted files are routinely opened.

Technical view

The issue is tied to wasm_dis() in libr/asm/arch/wasm/wasm.c, with upstream radare2 issue and commit references. The CVE text says a crafted WASM file can trigger an unspecified impact. The supplied sources do not identify affected versions, confirmed impact class, or complete remediation instructions.

Likely exposure

Exposure is most likely where radare2 or tools embedding its WASM disassembler process untrusted or attacker-supplied WASM files. The source bundle lists affected vendor and product as n/a, so exact asset matching requires local version and dependency validation.

Exploitation context

The supplied bundle does not cite active exploitation, public weaponization, or KEV inclusion. The threat scenario is malicious file parsing: a crafted WASM file reaches vulnerable disassembly logic during analysis or automated processing.

Researcher notes

The public record is sparse: no CVSS, CWE, affected versions, or precise impact are supplied. Analysis should stay anchored to the radare2 issue, commit, and local build provenance. Do not assume remote code execution or active exploitation from this bundle.

Mitigation direction

  • Check radare2 guidance and the referenced upstream commit.
  • Update radare2 to a version containing the upstream fix.
  • Avoid processing untrusted WASM files with unverified vulnerable tooling.
  • Run WASM analysis tools in a sandboxed, low-privilege environment.
  • Monitor vendor and distribution advisories for version-specific remediation.

Validation and detection

  • Inventory radare2 installations and embedded radare2 libraries.
  • Confirm whether installed builds include the referenced upstream commit.
  • Identify workflows that parse untrusted or external WASM files.
  • Review crash reports from WASM disassembly or analysis jobs.
  • Document any compensating sandboxing or isolation controls.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-11378 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.