---
title: "CVE-2022-39393\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-39393?format=md
keywords: index, follow
---

# CVE-2022-39393

Publication date 10 November 2022

Last updated 4 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.6 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2022-39393?format=md#impact-score)

Toggle side navigation

## Description

Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2
and 1.0.2, there is a bug in Wasmtime's implementation of its pooling
instance allocator where when a linear memory is reused for another
instance the initial heap snapshot of the prior instance can be visible,
erroneously to the next instance. This bug has been patched and users
should upgrade to Wasmtime 2.0.2 and 1.0.2. Other mitigations include
disabling the pooling allocator and disabling the `memory-init-cow`.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2022-39393?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| firefox | 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Ignored end of standard support, was needs-triage |
| 16.04 LTS xenial | Ignored end of standard support |
| 14.04 LTS trusty | Ignored end of standard support |
| mozjs38 | 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Ignored |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| mozjs52 | 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Ignored |
| 18.04 LTS bionic | Ignored |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| mozjs68 | 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Ignored |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| mozjs78 | 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Ignored end of life, was needs-triage |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Ignored |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| mozjs91 | 22.10 kinetic | Not in release |
| 22.04 LTS jammy | Ignored |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| thunderbird | 24.04 LTS noble | Ignored bundled deps handled by upstream in new versions |
| 23.10 mantic | Ignored end of life, was ignored [bundled deps handled by upstream in new versions] |
| 23.04 lunar | Ignored end of life, was ignored [bundled deps handled by upstream in new versions] |
| 22.10 kinetic | Ignored end of life, was needed |
| 22.04 LTS jammy | Ignored bundled deps handled by upstream in new versions |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Ignored end of standard support, was needed |
| 16.04 LTS xenial | Ignored end of standard support |
| 14.04 LTS trusty | Ignored end of standard support |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [tyhicks](https://launchpad.net/~tyhicks)

mozjs contains a copy of the SpiderMonkey JavaScript engine

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

starting with Ubuntu 22.04, the firefox package is just a script
that installs the Firefox snap

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.6 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Changed |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.6 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-39393)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-39393)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-39393)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-39393)

### Other references

* <https://github.com/bytecodealliance/wasmtime/commit/2614f2e9d2d36805ead8a8da0fa0c6e0d9e428a0>
* <https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-wh6w-3828-g9qf>
* <https://www.cve.org/CVERecord?id=CVE-2022-39393>
