{"id":"CVE-2025-13120","summary":"mruby array.c sort_cmp use after free","details":"A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/array.c. Such manipulation leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is eb398971bfb43c38db3e04528b68ac9a7ce509bc. It is advisable to implement a patch to correct this issue.","modified":"2026-08-12T13:32:52.878624Z","published":"2025-11-13T15:32:07.825Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13120.json"},"references":[{"type":"WEB","url":"https://github.com/mruby/mruby/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13120.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13120"},{"type":"ADVISORY","url":"https://vuldb.com/?id.332325"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.683435"},{"type":"REPORT","url":"https://github.com/makesoftwaresafe/mruby/pull/263"},{"type":"REPORT","url":"https://github.com/mruby/mruby/issues/6649"},{"type":"REPORT","url":"https://github.com/mruby/mruby/issues/6649#issue-3534393003"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.332325"},{"type":"FIX","url":"https://github.com/mruby/mruby/commit/eb398971bfb43c38db3e04528b68ac9a7ce509bc"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/makesoftwaresafe/mruby","events":[{"introduced":"0f45836b5954accf508f333f932741b925214471"},{"last_affected":"1bec3392300e99ea037a8e18aa9694c83390cea3"}],"database_specific":{"extracted_events":[{"introduced":"3.0"},{"last_affected":"3.0"},{"introduced":"3.1"},{"last_affected":"3.1"}],"source":"AFFECTED_FIELD"}},{"type":"GIT","repo":"https://github.com/mruby/mruby","events":[{"introduced":"0"},{"fixed":"eb398971bfb43c38db3e04528b68ac9a7ce509bc"}],"database_specific":{"cpe":"cpe:2.3:a:mruby:mruby:*:*:*:*:*:ruby:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.4.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.0","3.1","3.2","3.3","3.4.0","3.0.0-preview","1.2.0","1.1.0","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13120.json","vanir_signatures_modified":"2026-08-12T13:32:52Z","vanir_signatures":[{"target":{"file":"src/array.c"},"deprecated":false,"digest":{"line_hashes":["106735729729869236870795047255687425000","90299707028041641641292446968669987804","235598120627690113665834650147724635390","22976043955567767894389378994884520048","104341527859315864258126365558036500442","310438564539223903548213756483945658774","311892257740732880470878974558553218736","140229556377567758962507651173205991984","153955181957920876223572646275851522747","308466678630303098267546856925214420345","290749784403268547241825161301659604796","146310303753228597407784695875469933192","177301362055980948576603928402778731525","225717538188253171270909927789091858290","203436831666483383987340079647020245680","254224303390350337509807082607172893797","189885082185071567535083091730694334740","100588416079034929326720669240548647282","128548331433059251045607594590741994208","308870714209034894697290411824549845554"],"threshold":0.9},"id":"CVE-2025-13120-1e6e0fc9","signature_type":"Line","signature_version":"v1","source":"https://github.com/mruby/mruby/commit/eb398971bfb43c38db3e04528b68ac9a7ce509bc"},{"deprecated":false,"digest":{"function_hash":"34621261036828285842666461858266801461","length":559},"id":"CVE-2025-13120-205c1929","signature_type":"Function","signature_version":"v1","source":"https://github.com/mruby/mruby/commit/eb398971bfb43c38db3e04528b68ac9a7ce509bc","target":{"file":"src/array.c","function":"heapify"}},{"target":{"file":"src/array.c","function":"sort_cmp"},"deprecated":false,"digest":{"function_hash":"44244679024109628000605213618771014553","length":1224},"id":"CVE-2025-13120-919f0d23","signature_type":"Function","signature_version":"v1","source":"https://github.com/mruby/mruby/commit/eb398971bfb43c38db3e04528b68ac9a7ce509bc"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/mruby/mruby/commit/eb398971bfb43c38db3e04528b68ac9a7ce509bc","target":{"function":"insertion_sort","file":"src/array.c"},"deprecated":false,"digest":{"length":362,"function_hash":"315588603539289175991964389033193065737"},"id":"CVE-2025-13120-da4ae5ca"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}