-
-
Notifications
You must be signed in to change notification settings - Fork 227
GHSA SYNC: 1 brand new advisory #970
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Changes from all commits
bb0622b
201cf82
3cf1458
d756f4c
75881cb
48a80b7
af4d0de
4a345c8
d935a2d
6f0d6d4
3f4bc94
b823437
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,37 @@ | ||
| --- | ||
| engine: mruby | ||
| cve: 2025-7207 | ||
| ghsa: 48pr-6hvf-39v3 | ||
| url: https://nvd.nist.gov/vuln/detail/CVE-2025-7207 | ||
| title: Heap-based buffer overflow vulnerability in mruby 3.4.0 | ||
| date: 2025-07-08 | ||
| description: | | ||
| A vulnerability, which was classified as problematic, was found | ||
| in mruby up to 3.4.0. Affected is the function scope_new of | ||
| the file mrbgems/mruby-compiler/core/codegen.c of the component | ||
| nregs Handler. The manipulation leads to heap-based buffer overflow. | ||
| An attack has to be approached locally. The exploit has been | ||
| disclosed to the public and may be used. The name of the patch | ||
| is 1fdd96104180cc0fb5d3cb086b05ab6458911bb9. It is recommended | ||
| to apply a patch to fix this issue. | ||
| cvss_v2: 1.7 | ||
| cvss_v3: 5.5 | ||
| cvss_v4: 4.4 | ||
| notes: | | ||
| - Not patched - mruby 3.5.0 has not been released as of 2026/02/07. | ||
| - Found Issue #6509 listed in **unreleased** mruby 3.5 file listed below. | ||
| url: | ||
| - https://nvd.nist.gov/vuln/detail/CVE-2025-7207 | ||
| - https://github.com/mruby/mruby/blob/6f321251785c2396cb7e6a576ac2080c1adb4491/NEWS.md | ||
| - https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9.patch | ||
| - https://github.com/mruby/mruby/blob/master/NEWS.md | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The old URL is still there. |
||
| - https://mruby.org/releases/2025/04/20/mruby-3.4.0-released.html | ||
| - https://mruby.org/releases/2024/02/14/mruby-3.3.0-released.html | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Just curious why the 3.4.0 and 3.3.0 blog posts are listed as they do not fix issue 6509 or even mention it? |
||
| - https://github.com/mruby/mruby/commit/1fdd96104180cc0fb5d3cb086b05ab6458911bb9 | ||
| - https://github.com/mruby/mruby/issues/6509#event-17145516649 | ||
| - https://github.com/mruby/mruby/issues/6509 | ||
| - https://vuldb.com/?ctiid.315156 | ||
| - https://vuldb.com/?id.315156 | ||
| - https://vuldb.com/?submit.607683 | ||
| - https://www.wiz.io/vulnerability-database/cve/cve-2025-7207 | ||
| - https://github.com/advisories/GHSA-48pr-6hvf-39v3 | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Appears that
related:disappeared? This causesurl:to be consumed bynotes: |above.