CVE Vulnerabilities

CVE-2020-36401

Double Free

Published: Jul 01, 2021 | Modified: Jul 06, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Mruby Mruby 2.1.2 (including) 2.1.2 (including)
Mruby Ubuntu bionic *
Mruby Ubuntu esm-apps/jammy *
Mruby Ubuntu groovy *
Mruby Ubuntu hirsute *
Mruby Ubuntu impish *
Mruby Ubuntu jammy *
Mruby Ubuntu kinetic *
Mruby Ubuntu trusty *
Mruby Ubuntu upstream *
Mruby Ubuntu xenial *

Potential Mitigations

References