mruby 2.1.2 has a double free in mrbdefaultallocf (called from mrbfree and objfree).
{ "vanir_signatures": [ { "source": "https://github.com/mruby/mruby/commit/97319697c8f9f6ff27b32589947e1918e3015503", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "257450489011316511620633402431798244724", "291664367464202302924807726550456561833", "283430232777236476392833576910594740772", "916156461856379022783379629891076070" ] }, "target": { "file": "src/gc.c" }, "id": "CVE-2020-36401-0cef8eb3" }, { "source": "https://github.com/mruby/mruby/commit/97319697c8f9f6ff27b32589947e1918e3015503", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 326.0, "function_hash": "73814944348713604547654280989925281376" }, "target": { "file": "src/gc.c", "function": "mrb_realloc" }, "id": "CVE-2020-36401-f28469e6" } ] }