CVE-2022-28738
Severity CVSS v4.0:
Pending analysis
Type:
CWE-415
Double Free
Publication date:
09/05/2022
Last modified:
24/01/2024
Description
A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.0.4 (excluding) |
| cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | 3.1.0 (including) | 3.1.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



