CVE-2022-1201: NULL Pointer Dereference in mrb_vm_exec with super in mruby/mruby
Published Apr 2, 2022
·Updated
NULL Pointer Dereference in mrbvmexec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is capable of making the mruby interpreter crash, thus affecting the availability of the system.
Affected Software
1 affected component
mruby Mruby Ruby<3.2
Remediation
Event History
Apr 2, 2022
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-1201?
CVE-2022-1201 is a vulnerability that allows for a NULL pointer dereference in the mrb_vm_exec function in the mruby interpreter.
2
What is the severity of CVE-2022-1201?
The severity of CVE-2022-1201 is high, with a severity value of 6.5.
3
How does CVE-2022-1201 impact the system?
CVE-2022-1201 can cause the mruby interpreter to crash, affecting the availability of the system.
4
What software is affected by CVE-2022-1201?
The mruby repository prior to version 3.2 is affected by CVE-2022-1201.
5
How can CVE-2022-1201 be fixed?
Updating the mruby repository to version 3.2 or above will address CVE-2022-1201.