CVE-2022-28805
08.04.2022, 06:15
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.Enginsight
Vendor | Product | Version |
---|---|---|
lua | lua | 5.4.0 ≤ 𝑥 < 5.4.5 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
lua5.1 |
| ||||||||
lua5.2 |
| ||||||||
lua5.3 |
| ||||||||
lua5.4 |
| ||||||||
lua50 |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
lua5.1 |
| ||||||||||||||||||||
lua5.2 |
| ||||||||||||||||||||
lua5.3 |
| ||||||||||||||||||||
lua5.4 |
| ||||||||||||||||||||
lua50 |
|
Common Weakness Enumeration
References