CVE-2022-1071

Source
https://cve.org/CVERecord?id=CVE-2022-1071
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1071.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-1071
Downstream
Published
2022-03-26T03:40:10Z
Modified
2026-08-12T13:00:07.254667Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
User after free in mrb_vm_exec in mruby/mruby
Details

User after free in mrbvmexec in GitHub repository mruby/mruby prior to 3.2.

Database specific
{
    "cna_assigner": "@huntrdev",
    "cwe_ids": [
        "CWE-416"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1071.json"
}
References

Affected packages

Git / github.com/mruby/mruby

Affected ranges

Type
GIT
Repo
https://github.com/mruby/mruby
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mruby:mruby:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.1"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.0
1.1.0
1.2.0
3.*
3.0.0-preview

Database specific

vanir_signatures_modified
"2026-08-12T13:00:07Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1071.json"
vanir_signatures
[
    {
        "deprecated": false,
        "target": {
            "function": "mrb_vm_exec",
            "file": "src/vm.c"
        },
        "signature_type": "Function",
        "source": "https://github.com/mruby/mruby/commit/aaa28a508903041dd7399d4159a8ace9766b022f",
        "digest": {
            "length": 36749.0,
            "function_hash": "334154580191055838025194920808256077916"
        },
        "signature_version": "v1",
        "id": "CVE-2022-1071-6ef158bc"
    },
    {
        "deprecated": false,
        "target": {
            "file": "src/vm.c"
        },
        "signature_type": "Line",
        "source": "https://github.com/mruby/mruby/commit/aaa28a508903041dd7399d4159a8ace9766b022f",
        "digest": {
            "line_hashes": [
                "220203417436925363717173254796464404028",
                "190588191543741272317427159633541546037",
                "65748993201857808068708579703089743840",
                "120596547345232998383461388104095936629",
                "141328038235377773448573587792109436820",
                "181708859181679051255286190863904283731",
                "116428997302598538979115147492437614034",
                "17765579695051822423132429322802959994",
                "58749910528569234004158081582964920883",
                "230266232487780364689905212966169508332",
                "187187959805095875049851203380718724805",
                "25951067634640071345813032462824295267",
                "8098701169730744550730155180299996315",
                "103127932083229096565323125003595441142",
                "149926094135420737570090412559945427784",
                "84524763708519497709284279237131593519",
                "232167255891669320920589401499597327299",
                "208228825307844726982839986591127178421",
                "271053459941797077810671746538658809886",
                "59690397109214727671761870810085713878",
                "169424264637350014189491269847396735750",
                "14033104281619576515347241835029285999",
                "301991661479764603460557013164023984218",
                "62047442102183705477917573414947207736",
                "151622326815543634132812886571728831958",
                "295115554071708818745221801624797276315",
                "199131243331884488960072258061586923557",
                "281550416409626803243358410285396438577",
                "136295754585869265281100888548172804417"
            ],
            "threshold": 0.9
        },
        "signature_version": "v1",
        "id": "CVE-2022-1071-858888d6"
    }
]