Home

Description

EN DE

A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems/mruby-array-ext/src/array.c. Executing manipulation of the argument start/length can lead to out-of-bounds write. The attack needs to be launched locally. The exploit has been made available to the public and could be exploited. This patch is called 93619f06dd378db6766666b30c08978311c7ec94. It is best practice to apply a patch to resolve this issue.

In mruby 3.4.0 ist eine Schwachstelle entdeckt worden. Davon betroffen ist die Funktion ary_fill_exec der Datei mrbgems/mruby-array-ext/src/array.c. Mittels dem Manipulieren des Arguments start/length mit unbekannten Daten kann eine out-of-bounds write-Schwachstelle ausgenutzt werden. Der Angriff hat dabei lokal zu erfolgen. Der Exploit wurde der Öffentlichkeit bekannt gemacht und könnte verwendet werden. Der Patch heisst 93619f06dd378db6766666b30c08978311c7ec94. Es wird empfohlen, einen Patch anzuwenden, um dieses Problem zu beheben.

PUBLISHED Reserved 2025-11-07 | Published 2025-11-07 | Updated 2025-11-07 | Assigner VulDB




MEDIUM: 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 5.3CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
MEDIUM: 5.3CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
4.3AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Out-of-bounds Write

Memory Corruption

Timeline

2025-11-07:Advisory disclosed
2025-11-07:VulDB entry created
2025-11-07:VulDB entry last update

Credits

tjbecker (VulDB User) reporter

References

vuldb.com/?id.331511 (VDB-331511 | mruby array.c ary_fill_exec out-of-bounds write) vdb-entry technical-description

vuldb.com/?ctiid.331511 (VDB-331511 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.680879 (Submit #680879 | mruby 3.4.0 Out-of-bounds Write) third-party-advisory

github.com/mruby/mruby/issues/6650 issue-tracking

github.com/mruby/mruby/issues/6650 issue-tracking

github.com/mruby/mruby/issues/6650 exploit issue-tracking

github.com/...ommit/93619f06dd378db6766666b30c08978311c7ec94 patch

cve.org (CVE-2025-12875)

nvd.nist.gov (CVE-2025-12875)

Download JSON