CVE-2025-13397: S-Itoc Mruby/c
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file src/alloc.c. Such manipulation of the argument ptr leads to null pointer dereference. An attack has to be approached locally. The name of the patch is 009111904807b8567262036bf45297c3da8f1c87. It is advisable to implement a patch to correct this issue.
Affected products
- S-Itoc Mruby/c: up to and including 3.4
Published 2025-11-19. Last modified 2026-06-17.