Local Null Pointer Dereference in mrubyc Affected by Null Pointer Dereference Vulnerability
CVE-2025-13397
4.8MEDIUM
What is CVE-2025-13397?
A vulnerability has been identified in mrubyc versions up to 3.4, specifically within the mrbc_raw_realloc function in the src/alloc.c file. An attacker with local access may exploit this flaw by manipulating the ptr argument, resulting in a null pointer dereference. This can lead to unpredictable application behavior or crashes. It is essential for users of affected versions to apply the available patch named 009111904807b8567262036bf45297c3da8f1c87 to mitigate this risk.
Affected Version(s)
mrubyc 3.0
mrubyc 3.1
mrubyc 3.2
