Bug 1197581 - (CVE-2022-1106) VUL-0: CVE-2022-1106: mruby: use after free in mrb_vm_exec
(CVE-2022-1106)
VUL-0: CVE-2022-1106: mruby: use after free in mrb_vm_exec
Status: RESOLVED WORKSFORME
Classification: openSUSE
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security
Current
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Ferdinand Thiessen
Security Team bot
https://smash.suse.de/issue/327317/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-03-28 08:52 UTC by Thomas Leroy
Modified: 2022-04-26 19:27 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Thomas Leroy 2022-03-28 08:54:17 UTC
No version containing the fixing commit yet. openSUSE:Factory should be affected
Comment 2 Ferdinand Thiessen 2022-04-26 19:27:09 UTC
Version on Factory not affected, POC does not work.
Probably only the git version is affected not the 3.0 release (or fixed by other patch).

> % mruby POC
> trace (most recent call last):
> POC:1: undefined method 'cmp' (NoMethodError)