CVE-2024-25177: Null Pointer Dereference
Last updated 16 July 2026
Other sources
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IRFSTORE for NULL metatable, which leads to Denial of Service (DoS).
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/luajitto a version that resolves this vulnerability.Fixed in 2.1.0~beta3+dfsg-5.3+deb11u1Fixed in 2.1.0~beta3+git20220320+dfsg-4.1+deb12u1Fixed in 2.1.0+openresty20250117-2Fixed in 2.1.0+openresty20251030-1 - Upgrade
Upgrade
LuaJITto a version that resolves this vulnerability.Fixed in 2.1-20240314 - Upgrade
Upgrade
OpenRusty luajit2to a version that resolves this vulnerability.Fixed in v2.1-20240314
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25177?
CVE-2024-25177 is classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2024-25177?
To mitigate CVE-2024-25177, upgrade to a version of LuaJIT beyond 2.1.
What causes CVE-2024-25177 in LuaJIT?
CVE-2024-25177 is caused by unsinking of IR_FSTORE when a NULL metatable is encountered.
Which versions of LuaJIT are affected by CVE-2024-25177?
CVE-2024-25177 affects LuaJIT version 2.1 and earlier.
What type of attack can exploit CVE-2024-25177?
CVE-2024-25177 can be exploited to perform denial of service attacks.