CVE-2022-1071: User after free in mrb_vm_exec in mruby/mruby
Published Mar 26, 2022
·Updated
User after free in mrbvmexec in GitHub repository mruby/mruby prior to 3.2.
Affected Software
1 affected component
mruby mruby<=3.1
Remediation
Event History
Mar 26, 2022
CVE Published
via MITRE·03:40 AM
Data Sourced
via MITRE·03:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-1071?
CVE-2022-1071 is a vulnerability known as User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
2
What is the severity of CVE-2022-1071?
The severity of CVE-2022-1071 is high with a CVSS score of 8.2.
3
What software is affected by CVE-2022-1071?
Mruby version up to and including 3.1 is affected by CVE-2022-1071.
4
How can I fix CVE-2022-1071?
To fix CVE-2022-1071, update Mruby to version 3.2 or later.
5
Where can I find more information about CVE-2022-1071?
You can find more information about CVE-2022-1071 at the following references: [link1](https://github.com/mruby/mruby/commit/aaa28a508903041dd7399d4159a8ace9766b022f), [link2](https://huntr.dev/bounties/6597ece9-07af-415b-809b-919ce0a17cf3).