CVE-2017-9527: Debian Linux

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Mruby Mruby: up to and including 1.2.0

Published 2017-06-11. Last modified 2026-06-17.