CVE-2020-36401: Double Free
Published Jul 1, 2021
·Updated
mruby 2.1.2 has a double free in mrbdefaultallocf (called from mrbfree and objfree).
Affected Software
2 affected components
mruby mruby=2.1.2
Linux Linux kernel
Remediation
Patch Available
Event History
Jul 1, 2021
CVE Published
via MITRE·02:51 AM
Data Sourced
via MITRE·02:51 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-36401?
The severity of CVE-2020-36401 is high with a CVSS score of 7.8.
2
How does CVE-2020-36401 impact the affected software?
CVE-2020-36401 can lead to a double free vulnerability in mruby 2.1.2.
3
Which software versions are affected by CVE-2020-36401?
The affected software version is mruby 2.1.2.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-36401?
The CWE ID for CVE-2020-36401 is CWE-415.
5
How can I fix the vulnerability in mruby 2.1.2?
To fix the vulnerability in mruby 2.1.2, it is recommended to update to a patched version provided by the software vendor.