From =?UTF-8?Q?Moritz_M=C3=BChlenhoff?=@21:1/5 to All on Tue Jul 15 14:40:01 2025
Package: mruby
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for mruby.
CVE-2025-7207[0]:
| A vulnerability, which was classified as problematic, was found in
| mruby up to 3.4.0-rc2. Affected is the function scope_new of the
| file mrbgems/mruby-compiler/core/codegen.c of the component nregs
| Handler. The manipulation leads to heap-based buffer overflow. An
| attack has to be approached locally. The exploit has been disclosed
| to the public and may be used. The name of the patch is
| 1fdd96104180cc0fb5d3cb086b05ab6458911bb9. It is recommended to apply
| a patch to fix this issue.