PT-2025-28807 · Mruby+1 · Mruby+1
Jjleo
·
Published
2025-07-09
·
Updated
2025-10-01
·
CVE-2025-7207
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
mruby versions up to 3.4.0-rc2
Description:
A heap-based buffer overflow issue was found in the function
scope new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. This issue can be exploited locally.Recommendations:
For mruby versions up to 3.4.0-rc2, apply the patch 1fdd96104180cc0fb5d3cb086b05ab6458911bb9 to fix this issue. As a temporary workaround, consider restricting access to the
scope new function until the patch is applied.Exploit
Fix
Memory Corruption
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Mruby