CVE-2020-15866: Debian Linux

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

mruby through 2.1.2-rc has a heap-based buffer overflow in the mrb_yield_with_class function in vm.c because of incorrect VM stack handling. It can be triggered via the stack_copy function.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Mruby Mruby: up to and including 2.1.1; version 2.1.2 only

Published 2020-07-21. Last modified 2026-06-17.