CVE-2020-6838: Use After Free
Published Jan 11, 2020
·Updated
In mruby 2.1.0, there is a use-after-free in hashvaluesat in mrbgems/mruby-hash-ext/src/hash-ext.c.
Affected Software
1 affected component
mruby mruby=2.1.0
Event History
Jan 11, 2020
CVE Published
via MITRE·02:06 AM
Data Sourced
via MITRE·02:06 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-6838?
CVE-2020-6838 is a vulnerability in mruby 2.1.0 that allows for a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
2
How severe is CVE-2020-6838?
CVE-2020-6838 has a severity rating of 9.8, which is considered critical.
3
What software versions are affected by CVE-2020-6838?
Versions 2.1.0 of mruby are affected by CVE-2020-6838.
4
How can I fix CVE-2020-6838?
To fix CVE-2020-6838, it is recommended to update to a version of mruby that is not affected by the vulnerability.
5
Is there any additional information about CVE-2020-6838?
Yes, you can find more information about CVE-2020-6838 at the following reference: https://github.com/mruby/mruby/issues/4926