CVE-2022-4996 MEDIUM

CVE-2022-4996: mruby bigint.c udiv floating point comparison with incorrect operator

Vendor N/A
Product mruby
Weakness CWE-1077
Published August 19, 2026
Last update August 19, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.

Key dates

02Disclosure timeline

August 19, 2026 CVE published