Back

HIGH

lua: heap-based buffer over-read

Published Apr 10, 2023

Description

In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.

Affected products

Remediation

Red Hat statement

The bug exists in Lua Interpreter since v5.4.3 and fixed in v5.4.4. RHEL-6, 7, 8 ships Lua-v5.3.4 and prior versions, which does not contains the vulnerable function. And RHEL-9 already ships Lua-v5.4.4 and above, which contains the fix. Hence, none of the Lua versions shipped with Red Hat Enterprise Linux are affected.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 10, 2023
Updated Feb 12, 2025
Reserved Jan 3, 2022
CISA Vulnrichment
Updated Feb 12, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 10, 2023
ENISA EUVD
Assigner mitre
Published Apr 10, 2023
Updated Feb 12, 2025
Exploited since n/a
EUVD-2021-32691