UBUNTU-CVE-2026-1979

Source
https://ubuntu.com/security/CVE-2026-1979
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1979.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-1979
Upstream
Published
2026-02-06T05:16:00Z
Modified
2026-03-02T12:06:33.810395Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw has been found in mruby up to 3.4.0. This affects the function mrbvmexec of the file src/vm.c of the component JMPNOT-to-JMPIF Optimization. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been published and may be used. This patch is called e50f15c1c6e131fa7934355eb02b8173b13df415. It is advisable to implement a patch to correct this issue.

References

Affected packages

Ubuntu:16.04:LTS
mruby

Package

Name
mruby
Purl
pkg:deb/ubuntu/mruby@1.2.0+20160315+git4f20d58a-1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.1.0+20150817+gita1731254-1
1.1.0+20150906+git1cbbb7e1-1
1.2.0+20160315+git4f20d58a-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmruby-dev",
            "binary_version": "1.2.0+20160315+git4f20d58a-1"
        },
        {
            "binary_name": "mruby",
            "binary_version": "1.2.0+20160315+git4f20d58a-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1979.json"
Ubuntu:18.04:LTS
mruby

Package

Name
mruby
Purl
pkg:deb/ubuntu/mruby@1.4.0-1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.3.0-1
1.3.0+20170925+git38185028-1
1.3.0+20171029+git77edafb0-1
1.4.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmruby-dev",
            "binary_version": "1.4.0-1"
        },
        {
            "binary_name": "mruby",
            "binary_version": "1.4.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1979.json"
Ubuntu:20.04:LTS
mruby

Package

Name
mruby
Purl
pkg:deb/ubuntu/mruby@2.0.0-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmruby-dev",
            "binary_version": "2.0.0-1"
        },
        {
            "binary_name": "mruby",
            "binary_version": "2.0.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1979.json"
Ubuntu:22.04:LTS
mruby

Package

Name
mruby
Purl
pkg:deb/ubuntu/mruby@3.0.0-3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.1.2-3
3.*
3.0.0-1
3.0.0-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmruby-dev",
            "binary_version": "3.0.0-3"
        },
        {
            "binary_name": "mruby",
            "binary_version": "3.0.0-3"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1979.json"
Ubuntu:24.04:LTS
mruby

Package

Name
mruby
Purl
pkg:deb/ubuntu/mruby@3.2.0-2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.2.0-1
3.2.0-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmruby-dev",
            "binary_version": "3.2.0-2"
        },
        {
            "binary_name": "mruby",
            "binary_version": "3.2.0-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1979.json"
Ubuntu:25.10
mruby

Package

Name
mruby
Purl
pkg:deb/ubuntu/mruby@3.3.0-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.3.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libmruby-dev",
            "binary_version": "3.3.0-1"
        },
        {
            "binary_name": "mruby",
            "binary_version": "3.3.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-1979.json"