CVE-2022-1276: Out-of-bounds Read in mrb_get_args in mruby/mruby
Published Apr 10, 2022
·Updated
Out-of-bounds Read in mrbgetargs in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
Affected Software
1 affected component
mruby mruby<3.2
Remediation
Event History
Apr 10, 2022
CVE Published
via MITRE·09:35 AM
Data Sourced
via MITRE·09:35 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-1276?
CVE-2022-1276 is an out-of-bounds read vulnerability in the mrb_get_args function in the Mruby repository prior to version 3.2.
2
What is the severity of CVE-2022-1276?
The severity of CVE-2022-1276 is critical with a CVSS score of 9.8.
3
How can CVE-2022-1276 be exploited?
CVE-2022-1276 can be exploited to achieve arbitrary code execution.
4
Which software version is affected by CVE-2022-1276?
All versions of Mruby prior to 3.2 are affected by CVE-2022-1276.
5
How can I fix CVE-2022-1276?
To fix CVE-2022-1276, update Mruby to version 3.2 or newer.