Junglewise Threat Intelligence

CVE-2022-4996: mruby floating point comparison flaw in bigint division

CVE-2022-4996 · Severity: medium · CVSS 5.3 · Published 2026-08-20

Executive brief

mruby is a lightweight Ruby interpreter used in embedded systems and applications. A flaw in the bigint division function can be remotely exploited to cause incorrect floating point comparisons, potentially leading to logic errors or application crashes that impact availability or data integrity.

Technical details

The vulnerability is a floating point comparison logic error in the udiv function of bigint.c in mruby 3.1.0. The flaw stems from incorrect operator use when comparing floating point values during big integer division operations. The vulnerability is remotely exploitable with no authentication or user interaction required. An attacker can manipulate division operations to trigger incorrect comparisons, potentially causing incorrect calculation results or application instability. A patch is available and should be applied.

Affected products

  • mruby mruby 3.1.0

Timeline

  • 2026-08-20: disclosed

References

Related threats