PT-2025-28807 · Mruby+1 · Mruby+1

Jjleo

·

Published

2025-07-09

·

Updated

2025-10-01

·

CVE-2025-7207

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: mruby versions up to 3.4.0-rc2
Description: A heap-based buffer overflow issue was found in the function scope new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. This issue can be exploited locally.
Recommendations: For mruby versions up to 3.4.0-rc2, apply the patch 1fdd96104180cc0fb5d3cb086b05ab6458911bb9 to fix this issue. As a temporary workaround, consider restricting access to the scope new function until the patch is applied.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-7207
OPENSUSE-SU-2025:15333-1

Affected Products

Debian
Mruby