Upstream information
Description
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having moderate severity.
SUSE Bugzilla entry: 1280059 [NEW] No SUSE Security Announcements cross referenced.SUSE Timeline for this CVE
CVE page created: Fri Sep 11 15:39:43 2026CVE page last modified: Fri Sep 11 17:42:58 2026