CVE-2024-25178: Critical severity LuaJit LuaJIT vulnerability
Last updated 16 July 2026
Other sources
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in ljstate.c.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/luajitto a version that resolves this vulnerability.Fixed in 2.1.0~beta3+dfsg-5.3+deb11u1Fixed in 2.1.0~beta3+git20220320+dfsg-4.1+deb12u1Fixed in 2.1.0+openresty20250117-2Fixed in 2.1.0+openresty20251030-1 - Upgrade
Upgrade
LuaJITto a version that resolves this vulnerability.Fixed in 2.1-20240314 - Upgrade
Upgrade
OpenRusty luajit2to a version that resolves this vulnerability.Fixed in v2.1-20240314
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25178?
CVE-2024-25178 has a severity rating that indicates it poses a risk of out-of-bounds read vulnerabilities in LuaJIT.
How do I fix CVE-2024-25178?
To fix CVE-2024-25178, upgrade LuaJIT to version 2.1-20240314 or later.
What software versions are affected by CVE-2024-25178?
CVE-2024-25178 affects LuaJIT versions prior to 2.1-20240314.
What is the impact of CVE-2024-25178?
The impact of CVE-2024-25178 includes potential exploitation leading to stack overflow issues.
Is CVE-2024-25178 an active vulnerability?
As of now, CVE-2024-25178 is recognized as a vulnerability that could be actively exploited.