Use After Free Flaw in mruby by mruby
CVE-2026-1979
Key Information:
Badges
What is CVE-2026-1979?
A vulnerability exists in mruby versions up to 3.4.0, specifically in the mrb_vm_exec function within the JMPNOT-to-JMPIF Optimization component. This weakness allows an attacker to execute a manipulation that can result in a use after free condition. The attack needs to be launched locally, and an exploit has been published, suggesting an immediate need for remediation. A patch is available as e50f15c1c6e131fa7934355eb02b8173b13df415 to address this issue effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mruby 3.0
mruby 3.1
mruby 3.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
