#1149962 mruby: CVE-2026-79590

Package:
src:mruby
Source:
src:mruby
Submitter:
Salvatore Bonaccorso
Date:
2026-10-08 17:39:10 UTC
Severity:
normal
Tags:
#1149962#5
Date:
2026-10-04 19:14:14 UTC
From:
To:
Hi,

The following vulnerability was published for mruby.

CVE-2026-79590[0]:
| A NULL pointer dereference vulnerability exists in the Prism parser
| component of mruby 4.0.0. An attacker can provide a specially
| crafted Ruby source file that triggers the parser to pass a NULL
| pointer to nonnull string handling functions, resulting in undefined
| behavior and application crash.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-79590
https://www.cve.org/CVERecord?id=CVE-2026-79590
[1] https://github.com/mruby/mruby/issues/7032
[2] https://github.com/mruby/mruby/commit/c6866eed4ad5640b552ba79d16063e7ec70a0ac9

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore