A double free was found in the Regexp compiler in Ruby 3...
Critical severity
Unreviewed
Published
May 10, 2022
to the GitHub Advisory Database
•
Updated Jan 24, 2024
Description
Published by the National Vulnerability Database
May 9, 2022
Published to the GitHub Advisory Database
May 10, 2022
Last updated
Jan 24, 2024
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.
References