Search CVE reports


Toggle filters

11 – 16 of 16 results


CVE-2020-24342

Medium priority
Ignored

Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.

5 affected packages

lua5.1, lua5.2, lua5.3, lua5.4, lua50

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua5.1 — — Not affected Not affected Not affected
lua5.2 — — Not affected Not affected Not affected
lua5.3 — — Not affected Not affected Not affected
lua5.4 — — Not affected Not in release Not in release
lua50 — — Not in release Not affected Not affected
Show less packages

CVE-2020-15945

Low priority
Ignored

Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function.

5 affected packages

lua5.1, lua5.2, lua5.3, lua5.4, lua50

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua5.1 — — Not affected Not affected Not affected
lua5.2 — — Not affected Not affected Not affected
lua5.3 — — Not affected Not affected Not affected
lua5.4 — — Not affected Not in release Not in release
lua50 — — Not in release Not affected Not affected
Show less packages

CVE-2020-15889

Low priority
Not affected

Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members.

5 affected packages

lua5.1, lua5.2, lua5.3, lua5.4, lua50

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua5.1 — — — Not affected Not affected
lua5.2 — — — Not affected Not affected
lua5.3 — — — Not affected Not affected
lua5.4 — — — Not in release Not in release
lua50 — — — Not affected Not affected
Show less packages

CVE-2020-15888

Low priority
Ignored

Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.

5 affected packages

lua5.1, lua5.2, lua5.3, lua5.4, lua50

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua5.1 — — Not affected Not affected Not affected
lua5.2 — — Not affected Not affected Not affected
lua5.3 — — Not affected Not affected Not affected
lua5.4 — — Not affected Not in release Not in release
lua50 — — Not in release Not affected Not affected
Show less packages

CVE-2019-6706

Medium priority
Fixed

Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.

4 affected packages

lua5.1, lua5.2, lua5.3, lua50

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua5.1 — — — — Not affected
lua5.2 — — — — Not affected
lua5.3 — — — — Fixed
lua50 — — — — Not affected
Show less packages

CVE-2014-5461

Medium priority

Some fixes available 9 of 16

Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of...

3 affected packages

lua5.1, lua5.2, lua50

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lua5.1 — — — — —
lua5.2 — — — — —
lua50 — — — — —
Show less packages