MEDIUM
mruby JMPNOT-to-JMPIF Optimization vm.c mrb_vm_exec use after free
Published Feb 6, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.18%
Description
A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called e50f15c1c6e131fa7934355eb02b8173b13df415. It is advisable to implement a patch to correct this issue.
Affected products
-
- Version 3.0StatusaffectedConstraints-
- Version 3.1StatusaffectedConstraints-
- Version 3.2StatusaffectedConstraints-
- Version 3.3StatusaffectedConstraints-
- Version 3.4.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://github.com/mruby/mruby/ product
- https://github.com/mruby/mruby/issues/6701 issue-trackingExploitIssue Tracking
- https://github.com/mruby/mruby/issues/6701#issue-3802609843 exploitissue-trackingIssue Tracking
- https://github.com/sysfce2/mruby/commit/e50f15c1c6e131fa7934355eb02b8173b13df415 patch
- https://vuldb.com/?ctiid.344501 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.344501 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.743377 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://github.com/mruby/mruby/ | product | |
| https://github.com/mruby/mruby/issues/6701 | issue-trackingExploitIssue Tracking | |
| https://github.com/mruby/mruby/issues/6701#issue-3802609843 | exploitissue-trackingIssue Tracking | |
| https://github.com/sysfce2/mruby/commit/e50f15c1c6e131fa7934355eb02b8173b13df415 | patch | |
| https://vuldb.com/?ctiid.344501 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.344501 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.743377 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 6, 2026
Updated Feb 23, 2026
Reserved Feb 5, 2026
Link CVE-2026-1979
CISA Vulnrichment
Updated Feb 6, 2026