Bug 1197581 - (CVE-2022-1106) VUL-0: CVE-2022-1106: mruby: use after free in mrb_vm_exec
VUL-0: CVE-2022-1106: mruby: use after free in mrb_vm_exec
Classification: openSUSE
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Ferdinand Thiessen
Security Team bot
Depends on:
  Show dependency treegraph
Reported: 2022-03-28 08:52 UTC by Thomas Leroy
Modified: 2022-04-26 19:27 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Thomas Leroy 2022-03-28 08:54:17 UTC
No version containing the fixing commit yet. openSUSE:Factory should be affected
Comment 2 Ferdinand Thiessen 2022-04-26 19:27:09 UTC
Version on Factory not affected, POC does not work.
Probably only the git version is affected not the 3.0 release (or fixed by other patch).

> % mruby POC
> trace (most recent call last):
> POC:1: undefined method 'cmp' (NoMethodError)