Critical severity9.8NVD Advisory· Published Jul 21, 2020· Updated Jun 17, 2026
CVE-2020-15866
CVE-2020-15866
Description
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.
Affected products
5- mruby/mrubydescription
Patches
Vulnerability mechanics
References
2- github.com/mruby/mruby/issues/5042nvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/05/msg00006.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.