CVE-2022-1071
published 2022-03-26CVE-2022-1071: User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
PriorityP434high8.2CVSS 3.1
AVLACLPRLUIRSCCHIHAH
EPSS
0.91%
55.9th percentile
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mruby | < mruby 3.1.0-1 (bookworm) | mruby 3.1.0-1 (bookworm) |
| juniper | junos_os | — | — |
| juniper | mx_series | — | — |
| mruby | mruby | <= 3.1 | — |
| mruby | mruby | >= 0 < 3.1.0-1 | 3.1.0-1 |
| mruby | mruby | >= 0 < 3.1.0-1 | 3.1.0-1 |
| mruby | mruby | >= 0 < 3.1.0-1 | 3.1.0-1 |
| mruby | mruby_mruby | >= unspecified < 3.2 | 3.2 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
nvdv3.07.7HIGHCVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pv86-xgr9-75fj: User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3
ghsa_unreviewed·2022-03-27
CVE-2022-1071 [HIGH] CWE-416 GHSA-pv86-xgr9-75fj: User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
OSV
CVE-2022-1071: User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3
osv·2022-03-26·CVSS 8.2
CVE-2022-1071 [HIGH] CVE-2022-1071: User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
Juniper
CVE-2022-22249: An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series a
vendor_juniper·2022-10-18·CVSS 6.5
CVE-2022-22249 [MEDIUM] CWE-664 CVE-2022-22249: An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series a
CVE-2022-22249: An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory corruption causes one or more FPCs to crash and reboot. These MAC moves can be between two local interfaces or between core/EVPN and local interface. The below error logs can be seen in PFE syslog when this issue happens: xss_event_handler(1071): EA[0:0]_PPE 46.xss[0] ADDR Error. ppe_error_interrupt(4298): EA[0:0]_PPE 46 Errors sync xtxn error xss_event_handler(1071): EA[0:0]_PPE 1.xss[0] ADDR Error. ppe_error_interrupt(4298): EA[0:0]_PPE 1 Errors sync xtxn error xss_event_handler(1071): EA[0:0]_PPE 2.xss
Debian
CVE-2022-1071: mruby - User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
vendor_debian·2022·CVSS 8.2
CVE-2022-1071 [HIGH] CVE-2022-1071: mruby - User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
Scope: local
bookworm: resolved (fixed in 3.1.0-1)
bullseye: open
forky: resolved (fixed in 3.1.0-1)
sid: resolved (fixed in 3.1.0-1)
trixie: resolved (fixed in 3.1.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-26
Published