mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mruby | Mruby | 2.1.2 (including) | 2.1.2 (including) |
Mruby | Ubuntu | bionic | * |
Mruby | Ubuntu | esm-apps/jammy | * |
Mruby | Ubuntu | groovy | * |
Mruby | Ubuntu | hirsute | * |
Mruby | Ubuntu | impish | * |
Mruby | Ubuntu | jammy | * |
Mruby | Ubuntu | kinetic | * |
Mruby | Ubuntu | trusty | * |
Mruby | Ubuntu | upstream | * |
Mruby | Ubuntu | xenial | * |