PT-2025-45500 · Mruby · Mruby
Tjbecker
·
Published
2025-11-07
·
Updated
2025-11-08
·
CVE-2025-12875
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mruby version 3.4.0
Description
A flaw exists in mruby version 3.4.0 within the
ary fill exec function located in the file mrbgems/mruby-array-ext/src/array.c. Manipulation of the start and length arguments can result in an out-of-bounds write. This issue requires local access to exploit. The exploit code has been publicly released.Recommendations
Apply patch 93619f06dd378db6766666b30c08978311c7ec94.
Exploit
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mruby