CVE-2022-28805
08.04.2022, 06:15
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.Enginsight
| Vendor | Product | Version |
|---|---|---|
| lua | lua | 5.4.0 ≤ 𝑥 < 5.4.5 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| lua5.1 |
| ||||||||
| lua5.2 |
| ||||||||
| lua5.3 |
| ||||||||
| lua5.4 |
| ||||||||
| lua50 |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| lua5.1 |
| ||||||||||||||||||||
| lua5.2 |
| ||||||||||||||||||||
| lua5.3 |
| ||||||||||||||||||||
| lua5.4 |
| ||||||||||||||||||||
| lua50 |
|
Common Weakness Enumeration
References