Executive brief
mruby is a lightweight Ruby interpreter used in embedded systems and applications. A flaw in the bigint division function can be remotely exploited to cause incorrect floating point comparisons, potentially leading to logic errors or application crashes that impact availability or data integrity.
Technical details
The vulnerability is a floating point comparison logic error in the udiv function of bigint.c in mruby 3.1.0. The flaw stems from incorrect operator use when comparing floating point values during big integer division operations. The vulnerability is remotely exploitable with no authentication or user interaction required. An attacker can manipulate division operations to trigger incorrect comparisons, potentially causing incorrect calculation results or application instability. A patch is available and should be applied.
Affected products
- mruby mruby 3.1.0
Timeline
- 2026-08-20: disclosed