First published: Fri Jul 01 2022(Updated: )
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lua Lua | >=5.4.2<=5.4.4 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
debian/lua5.1 | 5.1.5-8.1 5.1.5-9 | |
debian/lua5.2 | 5.2.4-1.1 5.2.4-3 | |
debian/lua5.3 | 5.3.3-1.1+deb11u1 5.3.6-2 | |
debian/lua5.4 | <=5.4.2-2 | 5.4.4-3+deb12u1 5.4.6-3 |
debian/lua50 | 5.0.3-8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-33099.
The severity level of CVE-2022-33099 is high, with a CVSS score of 7.5.
CVE-2022-33099 affects Lua v5.4.4 and below.
CVE-2022-33099 leads to a heap-buffer overflow when a recursive error occurs.
Yes, you can find references related to CVE-2022-33099 at the following links: [link1](https://github.com/lua/lua/commit/42d40581dd919fb134c07027ca1ce0844c670daf), [link2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/), [link3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UHYZOEFDVLVAD6EEP4CDW6DNONIVVHPA/)