singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade luaUpgrade lua-libsUpgrade lua-devel | May 15, 2023 | Apr 8, 2022 |
| Alpine Linux | — | Upgrade lua5.4 | Mar 26, 2024 | Apr 8, 2022 |
| Centos_linux | — | Upgrade lua-debuginfoUpgrade lua-debugsourceUpgrade lua-libs-debuginfoUpgrade lua-libsUpgrade lua | May 15, 2023 | Apr 8, 2022 |
| Debian | — | Upgrade lua5.4 | Jul 30, 2024 | Apr 8, 2022 |
| Gentoo Linux | — | Upgrade dev-lang/lua. | May 4, 2023 | Apr 8, 2022 |
| Oracle_linux | — | Upgrade luaUpgrade lua-libsUpgrade lua-devel | May 17, 2023 | Apr 8, 2022 |
| Redhat_linux | — | Upgrade luaUpgrade lua-libs-debuginfoUpgrade lua-debuginfoUpgrade lua-debugsourceUpgrade lua-libsUpgrade lua-devel | May 15, 2023 | Apr 8, 2022 |
| Ubuntu | — | Upgrade lua5.4 (Ubuntu Pro) | Jul 31, 2024 | Apr 8, 2022 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 8, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub