Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-38976

CVE-2026-38976: mrubyc NULL Pointer Dereference Flaw

CVE-2026-38976 is a NULL pointer dereference in mrubyc through 3.4.1 affecting op_super() in src/vm.c. This critical flaw can cause crashes. This post covers technical details, affected versions, and mitigations.

Published:

CVE-2026-38976 Overview

CVE-2026-38976 is a NULL pointer dereference vulnerability affecting mrubyc through version 3.4.1. The flaw resides in src/vm.c within the op_super() function handling the OP_SUPER opcode. A missing runtime guard allows a super invocation at the top level, outside of any method context, causing the interpreter to dereference a NULL callinfo pointer and crash. The issue is classified under [CWE-476] (NULL Pointer Dereference) and impacts the availability of applications embedding the mruby/c virtual machine.

Critical Impact

Attackers who can supply or influence mruby/c bytecode can trigger an availability-impacting crash of the interpreter, resulting in denial of service for embedded and IoT workloads relying on mrubyc.

Affected Products

  • mrubyc through 3.4.1
  • Embedded applications and IoT firmware bundling the mruby/c virtual machine
  • Downstream projects consuming vulnerable src/vm.c builds

Discovery Timeline

  • 2026-07-06 - CVE-2026-38976 published to NVD
  • 2026-07-07 - Last updated in NVD database

Technical Details for CVE-2026-38976

Vulnerability Analysis

The mruby/c virtual machine implements Ruby's super keyword through the OP_SUPER opcode, dispatched by the op_super() function in src/vm.c. When executing super, the VM resolves the parent class by consulting the current call frame stored in vm->callinfo_tail. The implementation assumed this pointer would always be valid because super is typically only reachable from within a method body.

The vulnerability breaks that assumption. When Ruby source containing a top-level super call is compiled to bytecode and executed, no call frame has been pushed. The callinfo_tail field is NULL, and dereferencing it to access callinfo->own_class crashes the interpreter. This affects any host process that evaluates untrusted or attacker-influenced mruby/c bytecode.

Root Cause

The root cause is a missing runtime precondition check in op_super(). The function directly dereferences vm->callinfo_tail without verifying the current execution context contains an active method frame. Ruby semantics permit parsing super outside a method, so the compiler produces valid bytecode that the VM cannot safely execute.

Attack Vector

An attacker supplies crafted Ruby source or precompiled mruby/c bytecode containing a top-level super expression. When the host application evaluates the input, the VM crashes with a NULL pointer dereference. In network-facing services or IoT devices that accept user scripts, this yields a remote denial-of-service condition.

c
// Security patch in src/vm.c - adds crash guard for top-level super
// fixes mrubyc issue #276

   // find super class
   mrbc_callinfo *callinfo = vm->callinfo_tail;
+  if( callinfo == NULL ) {
+    mrbc_raise(vm, MRBC_CLASS(NoMethodError), "super called outside of method");
+    return;
+  }
   mrbc_class *cls = callinfo->own_class;
   mrbc_method method;

Source: GitHub Commit c4aa2a0. The patch checks callinfo for NULL before use and raises a NoMethodError instead of dereferencing an invalid pointer.

Detection Methods for CVE-2026-38976

Indicators of Compromise

  • Unexpected process termination or segmentation faults in applications embedding the mruby/c interpreter
  • Core dumps referencing op_super or vm->callinfo_tail in the call stack
  • Repeated crashes of IoT firmware or embedded services shortly after receiving user-supplied script input

Detection Strategies

  • Perform static inspection of deployed binaries and firmware images to identify vulnerable mrubyc versions at or below 3.4.1
  • Scan Ruby source or mruby/c bytecode inputs for super invocations occurring outside of a def block
  • Instrument the VM host process with crash reporting to capture NULL dereference faults originating in src/vm.c

Monitoring Recommendations

  • Aggregate application crash telemetry from endpoints and IoT devices into a centralized logging pipeline for correlation
  • Alert on repeated interpreter restarts or watchdog-triggered reboots on devices running mruby/c workloads
  • Track ingress of untrusted scripts and correlate with subsequent process failures on the executing host

How to Mitigate CVE-2026-38976

Immediate Actions Required

  • Inventory all systems, firmware images, and applications that embed mrubyc and identify versions at or below 3.4.1
  • Apply the upstream fix from commit c4aa2a0 or upgrade to a release incorporating the top-level super guard
  • Restrict execution of untrusted mruby/c bytecode until patched builds are deployed

Patch Information

The fix is committed in the mrubyc repository and adds a NULL check for callinfo in op_super(), raising a NoMethodError when super is invoked outside a method. See the GitHub commit c4aa2a0, the mrubyc project repository, and the issue #276 discussion for context.

Workarounds

  • Reject or pre-parse user-supplied Ruby source and refuse programs that contain super at the top level
  • Sandbox the mruby/c interpreter in a supervised child process that can be restarted safely after a crash
  • Disable script upload or evaluation endpoints exposed to untrusted networks until the patched build is installed
bash
# Rebuild mrubyc from patched source
git clone https://github.com/mrubyc/mrubyc.git
cd mrubyc
git fetch origin
git checkout c4aa2a06bfdd13a0f1ae5165c5760a2530314a42
make clean && make
# Redeploy the patched libmrubyc into dependent firmware/applications

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.