A flaw has been found in mruby up to 3.4.0. This affects the function mrb_vm_exec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called e50f15c1c6e131fa7934355eb02b8173b13df415. It is advisable to implement a patch to correct this issue.
References
| Link | Resource |
|---|---|
| https://github.com/mruby/mruby/ | Product |
| https://github.com/mruby/mruby/issues/6701 | Exploit Issue Tracking |
| https://github.com/mruby/mruby/issues/6701#issue-3802609843 | Exploit Issue Tracking |
| https://github.com/sysfce2/mruby/commit/e50f15c1c6e131fa7934355eb02b8173b13df415 | Patch |
| https://vuldb.com/?ctiid.344501 | Permissions Required VDB Entry |
| https://vuldb.com/?id.344501 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.743377 | Third Party Advisory VDB Entry |
Configurations
History
28 Feb 2026, 00:33
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mruby:mruby:*:*:*:*:*:ruby:*:* | |
| Summary |
|
|
| First Time |
Mruby mruby
Mruby |
|
| References | () https://github.com/mruby/mruby/ - Product | |
| References | () https://github.com/mruby/mruby/issues/6701 - Exploit, Issue Tracking | |
| References | () https://github.com/mruby/mruby/issues/6701#issue-3802609843 - Exploit, Issue Tracking | |
| References | () https://github.com/sysfce2/mruby/commit/e50f15c1c6e131fa7934355eb02b8173b13df415 - Patch | |
| References | () https://vuldb.com/?ctiid.344501 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.344501 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.743377 - Third Party Advisory, VDB Entry |
06 Feb 2026, 05:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-06 05:16
Updated : 2026-02-28 00:33
NVD link : CVE-2026-1979
Mitre link : CVE-2026-1979
CVE.ORG link : CVE-2026-1979
JSON object : View
Products Affected
mruby
- mruby
