Local Null Pointer Dereference in mrubyc Affected by Null Pointer Dereference Vulnerability
CVE-2025-13397

4.8MEDIUM

Key Information:

Vendor

mrubyc

Status
Vendor
CVE Published:
19 November 2025

What is CVE-2025-13397?

A vulnerability has been identified in mrubyc versions up to 3.4, specifically within the mrbc_raw_realloc function in the src/alloc.c file. An attacker with local access may exploit this flaw by manipulating the ptr argument, resulting in a null pointer dereference. This can lead to unpredictable application behavior or crashes. It is essential for users of affected versions to apply the available patch named 009111904807b8567262036bf45297c3da8f1c87 to mitigate this risk.

Affected Version(s)

mrubyc 3.0

mrubyc 3.1

mrubyc 3.2

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

micromilo (VulDB User)
.