The markcontextstack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.4.0-1", "binary_name": "libmruby-dev" }, { "binary_version": "1.4.0-1", "binary_name": "mruby" }, { "binary_version": "1.4.0-1", "binary_name": "mruby-dbgsym" } ] }