PT-2025-45500 · Mruby · Mruby

·

CVE-2025-12875

·

Published

2025-11-07

·

Updated

2025-11-08

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mruby version 3.4.0
Description A flaw exists in mruby version 3.4.0 within the ary fill exec function located in the file mrbgems/mruby-array-ext/src/array.c. Manipulation of the start and length arguments can result in an out-of-bounds write. This issue requires local access to exploit. The exploit code has been publicly released.
Recommendations Apply patch 93619f06dd378db6766666b30c08978311c7ec94.

Exploit

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12875

Affected Products

Mruby