First published: Mon Apr 10 2023(Updated: )
<p>This CVE was assigned by Mitre. Some Microsoft products consume <a href="https://lua.org/about.html">Lau open-source software</a>. The purpose of this document is to attest to the fact that the products listed in the Security Updates table have been updated to protect against this vulnerability.</p>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =21H2 | |
Microsoft Windows 11 | =22H2 | |
Microsoft CBL Mariner 2.0 ARM | ||
Microsoft Windows 11 | =24H2 | |
Microsoft Windows Server 2025 | ||
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2025 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 10 | =22H2 | |
Microsoft Windows 11 | =24H2 | |
Microsoft Windows 10 | =21H2 | |
Microsoft Windows Server 2022, 23H2 Edition | ||
Microsoft Windows Server 2022 | ||
Microsoft Windows 11 | =23H2 | |
Microsoft Windows 11 | =22H2 | |
Microsoft Windows 11 | =23H2 | |
Microsoft CBL Mariner 2.0 x64 | ||
Microsoft Windows 10 | =22H2 | |
Microsoft Azure Linux 3.0 x64 | ||
Microsoft Windows Server 2022 | ||
Microsoft Azure Linux 3.0 ARM | ||
Lua | =5.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45985 is a vulnerability in Lua 5.4.3 that causes an erroneous finalizer to be called during a tail call, leading to a heap-based buffer over-read.
The severity of CVE-2021-45985 is high, with a severity value of 7.5.
CVE-2021-45985 can cause a heap-based buffer over-read in Lua 5.4.3 due to an erroneous finalizer called during a tail call.
To fix CVE-2021-45985, update Lua to version 5.4.4 or later, which includes a patch for the vulnerability.
You can find more information about CVE-2021-45985 on the Lua mailing list, Lua GitHub repository, and Lua bug tracker.