CVE-2020-15866: Debian Linux
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.
Affected products
Published 2020-07-21. Last modified 2026-06-17.