CVE-2020-15890: High severity luajit vulnerability
Last updated 26 August 2025
Other sources
LuaJit through 2.1.0-beta3 has an out-of-bounds read because gc handler frame traversal is mishandled.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15890?
CVE-2020-15890 is a vulnerability in LuaJit that allows an out-of-bounds read due to mishandled __gc handler frame traversal.
What is the severity of CVE-2020-15890?
The severity of CVE-2020-15890 is high with a CVSS score of 7.5.
Which software is affected by CVE-2020-15890?
The affected software includes LuaJit versions up to and including 2.0.4+dfsg-1+ on Ubuntu, Luajit versions up to and including 2.0.4+dfsg-1+ on Xenial, and Luajit versions up to and including 2.1.0~beta3+git20220320+dfsg-4.1 on Debian.
How can I fix CVE-2020-15890 on Ubuntu?
To fix CVE-2020-15890 on Ubuntu, update the luajit package to version 2.0.4+dfsg-1+ or later.
How can I fix CVE-2020-15890 on Debian?
To fix CVE-2020-15890 on Debian, update the luajit package to version 2.1.0~beta3+git20220320+dfsg-4.1 or later.