VYPR
Critical severity9.8NVD Advisory· Published Jul 21, 2020· Updated Jun 17, 2026

CVE-2020-15866

CVE-2020-15866

Description

mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.

Affected products

5
  • mruby/mrubydescription
  • Mruby/Mruby3 versions
    cpe:2.3:a:mruby:mruby:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:mruby:mruby:*:*:*:*:*:*:*:*range: <=2.1.1
    • cpe:2.3:a:mruby:mruby:2.1.2:rc:*:*:*:*:*:*
    • (no CPE)range: <=2.1.2-rc
  • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.