CVE-2020-15890Out-of-bounds Read in Luajit

CWE-125Out-of-bounds Read12 documents8 sources
Severity
7.5HIGHNVD
EPSS
1.0%
top 23.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 21
Latest updateMay 24

Description

LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianluajit/luajit< 2.1.0~beta3+dfsg-5.3+deb11u1+3
Ubuntuluajit/luajit< 2.0.4+dfsg-1+deb9u1build0.16.04.1
NVDluajit/luajit2.0.5+1

Also affects: Debian Linux 9.0, Ubuntu Linux 16.04

🔴Vulnerability Details

4
GHSA
GHSA-fv6p-x8x2-5jcc: LuaJit through 22022-05-24
OSV
luajit vulnerability2020-09-15
CVEList
CVE-2020-15890: LuaJit through 22020-07-21
OSV
CVE-2020-15890: LuaJit through 22020-07-21

📋Vendor Advisories

3
Ubuntu
LuaJIT vulnerability2020-09-15
Red Hat
luajit: out-of-bounds read because __gc handler frame traversal is mishandled2020-07-11
Debian
CVE-2020-15890: luajit - LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame ...2020

💬Community

4
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [openstack-rdo]2020-07-28
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [epel-all]2020-07-24
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled2020-07-24
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [fedora-all]2020-07-24
CVE-2020-15890 — Out-of-bounds Read in Luajit | cvebase