CVE-2025-7207 | mruby up to 3.4.0-rc2 nregs codegen.c scope_new heap-based overflow (Issue 6509 / EUVD-2025-20759)
A vulnerability, which was classified as problematic, was found in mruby up to 3.4.0-rc2. Affected is the function scope_new of the file mrbgems/mruby-compiler/core/codegen.c of the component nregs Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2025-7207. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.