CVE-2025-7207: mruby nregs codegen.c scope_new heap-based overflow
A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scopenew of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 1fdd96104180cc0fb5d3cb086b05ab6458911bb9. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mrubyto a version that resolves this vulnerability.Patch 1fdd96104180cc0fb5d3cb086b05ab6458911bb9
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7207?
CVE-2025-7207 is classified as a problematic vulnerability due to its potential for heap-based buffer overflow.
How do I fix CVE-2025-7207?
To mitigate CVE-2025-7207, upgrade mruby to a version later than 3.4.0-rc2 that addresses the vulnerability.
What components are affected by CVE-2025-7207?
CVE-2025-7207 affects the nregs Handler within the scope_new function in mruby versions up to 3.4.0-rc2.
What type of attack can be conducted through CVE-2025-7207?
An attacker can exploit CVE-2025-7207 to perform heap-based buffer overflow attacks.
Who is responsible for patching CVE-2025-7207?
It is the responsibility of maintainers and users of mruby to apply patches and updates to mitigate CVE-2025-7207.