MEDIUM
mruby bigint.c udiv floating point comparison with incorrect operator
Published Aug 19, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.64%
Description
A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.
Affected products
-
Affected
- 3.1.0
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-56020 Advisory
- https://huntr.com/bounties/5a5092df-1699-4497-a8b2-38318bce0c4e exploit
- https://vuldb.com/cve/CVE-2022-4996 third-party-advisory
- https://vuldb.com/submit/877513 third-party-advisory
- https://vuldb.com/vuln/391391 vdb-entrytechnical-description
- https://vuldb.com/vuln/391391/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-56020 | Advisory | |
| https://huntr.com/bounties/5a5092df-1699-4497-a8b2-38318bce0c4e | exploit | |
| https://vuldb.com/cve/CVE-2022-4996 | third-party-advisory | |
| https://vuldb.com/submit/877513 | third-party-advisory | |
| https://vuldb.com/vuln/391391 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/391391/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 19, 2026
Updated Aug 21, 2026
Reserved Aug 17, 2026
Link CVE-2022-4996
CISA Vulnrichment
Updated Aug 21, 2026
Red Hat
No data
GitHub
No data