CVE Vulnerabilities

CVE-2020-36401

Double Free

Published: Jul 01, 2021 | Modified: Jul 06, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free).

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Mruby Mruby 2.1.2 (including) 2.1.2 (including)

Potential Mitigations

References