CVE-2021-44647: Medium severity Lua Lua vulnerability
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.2.1-5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.6.27-3
Event History
Frequently Asked Questions
What is CVE-2021-44647?
CVE-2021-44647 is a vulnerability in Lua v5.4.3 and above that can cause a local denial of service due to a type confusion in the funcnamefromcode function in ldebug.c.
How does CVE-2021-44647 affect Lua?
CVE-2021-44647 affects Lua v5.4.3 and above, potentially leading to a local denial of service.
What is the severity of CVE-2021-44647?
The severity of CVE-2021-44647 is medium, with a severity value of 5.5.
How can I fix CVE-2021-44647?
To fix CVE-2021-44647, update to a version of Lua that addresses the vulnerability.
Where can I find more information about CVE-2021-44647?
You can find more information about CVE-2021-44647 on the Lua mailing list and the Red Hat CVE database.