PT-2025-45500 · Mruby · Mruby

Tjbecker

·

Published

2025-11-07

·

Updated

2025-11-08

·

CVE-2025-12875

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mruby version 3.4.0
Description A flaw exists in mruby version 3.4.0 within the ary fill exec function located in the file mrbgems/mruby-array-ext/src/array.c. Manipulation of the start and length arguments can result in an out-of-bounds write. This issue requires local access to exploit. The exploit code has been publicly released.
Recommendations Apply patch 93619f06dd378db6766666b30c08978311c7ec94.

Exploit

Fix

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-12875

Affected Products

Mruby