CVE-2020-15890
published 2020-07-21CVE-2020-15890: LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.86%
85.4th percentile
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | luajit | < luajit 2.1.0~beta3+git20210112+dfsg-2 (bookworm) | luajit 2.1.0~beta3+git20210112+dfsg-2 (bookworm) |
| luajit | luajit | <= 2.0.5 | — |
| luajit | luajit | — | — |
| luajit | luajit | >= 0 < 2.1.0~beta3+dfsg-5.3+deb11u1 | 2.1.0~beta3+dfsg-5.3+deb11u1 |
| luajit | luajit | >= 0 < 2.1.0~beta3+git20210112+dfsg-2 | 2.1.0~beta3+git20210112+dfsg-2 |
| luajit | luajit | >= 0 < 2.1.0~beta3+git20210112+dfsg-2 | 2.1.0~beta3+git20210112+dfsg-2 |
| luajit | luajit | >= 0 < 2.1.0~beta3+git20210112+dfsg-2 | 2.1.0~beta3+git20210112+dfsg-2 |
| luajit | luajit | >= 0 < 2.0.4+dfsg-1+deb9u1build0.16.04.1 | 2.0.4+dfsg-1+deb9u1build0.16.04.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LuaJIT vulnerability
vendor_ubuntu·2020-09-15·CVSS 7.5
CVE-2020-15890 [HIGH] LuaJIT vulnerability
Title: LuaJIT vulnerability
Summary: LuaJIT could be made crash or expose sensitive information if it received
specially crafted input.
It was discovered that an out-of-bounds read existed in LuaJIT. An
attacker could use this to cause a denial of service (application crash)
or possibly expose sensitive information. (CVE-2020-15890)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
luajit: out-of-bounds read because __gc handler frame traversal is mishandled
vendor_redhat·2020-07-11·CVSS 7.5
CVE-2020-15890 [HIGH] CWE-125 luajit: out-of-bounds read because __gc handler frame traversal is mishandled
luajit: out-of-bounds read because __gc handler frame traversal is mishandled
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
A flaw was found in luajit. An out-of-bounds read can occur due to a frame traversal being mishandled.
Statement: OpenShift ServiceMesh proxy does package a vulnerable version of luajit. The segmentation fault is triggered via creating a inline code rule in the envoy filter, however envoy can also be caused to exit via a code rule which is also not syntactically correct either. A user who has permissions to change the filter rule can have the same affect regardless, hence this issue will not be addressed at this time and might be fixed in a future release.
Package: servicemesh-proxy (OpenShift Service Mesh
Debian
CVE-2020-15890: luajit - LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame ...
vendor_debian·2020·CVSS 7.5
CVE-2020-15890 [HIGH] CVE-2020-15890: luajit - LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame ...
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
Scope: local
bookworm: resolved (fixed in 2.1.0~beta3+git20210112+dfsg-2)
bullseye: resolved (fixed in 2.1.0~beta3+dfsg-5.3+deb11u1)
forky: resolved (fixed in 2.1.0~beta3+git20210112+dfsg-2)
sid: resolved (fixed in 2.1.0~beta3+git20210112+dfsg-2)
trixie: resolved (fixed in 2.1.0~beta3+git20210112+dfsg-2)
GHSA
GHSA-fv6p-x8x2-5jcc: LuaJit through 2
ghsa_unreviewed·2022-05-24
CVE-2020-15890 [MEDIUM] CWE-125 GHSA-fv6p-x8x2-5jcc: LuaJit through 2
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
OSV
luajit vulnerability
osv·2020-09-15·CVSS 7.5
CVE-2020-15890 [HIGH] luajit vulnerability
luajit vulnerability
It was discovered that an out-of-bounds read existed in LuaJIT. An
attacker could use this to cause a denial of service (application crash)
or possibly expose sensitive information. (CVE-2020-15890)
OSV
CVE-2020-15890: LuaJit through 2
osv·2020-07-21·CVSS 7.5
CVE-2020-15890 [HIGH] CVE-2020-15890: LuaJit through 2
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [openstack-rdo]
bugzilla·2020-07-28·CVSS 7.5
CVE-2020-15890 [HIGH] CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [openstack-rdo]
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
luaji
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [epel-all]
bugzilla·2020-07-24·CVSS 7.5
CVE-2020-15890 [HIGH] CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [epel-all]
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled
bugzilla·2020-07-24·CVSS 7.5
CVE-2020-15890 [HIGH] CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled
LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled.
References
https://github.com/LuaJIT/LuaJIT/issues/601
Discussion:
Created luajit tracking bugs for this issue:
Affects: epel-all [bug 1860331]
Affects: fedora-all [bug 1860330]
---
Created luajit tracking bugs for this issue:
Affects: openstack-rdo [bug 1861551]
---
Upstream fix: https://github.com/LuaJIT/LuaJIT/commit/53f82e6e2e858a0a62fd1a2ff47e9866693382e6
---
Statement:
OpenShift ServiceMesh proxy does package a vulnerable version of luajit. The segmentation fault is triggered via creating a inline code rule in the envoy filter, however envoy can also be caused to exit via a co
Bugzilla
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [fedora-all]
bugzilla·2020-07-24·CVSS 7.5
CVE-2020-15890 [HIGH] CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [fedora-all]
CVE-2020-15890 luajit: out-of-bounds read because __gc handler frame traversal is mishandled [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
https://github.com/LuaJIT/LuaJIT/issues/601https://lists.debian.org/debian-lts-announce/2020/07/msg00026.htmlhttps://usn.ubuntu.com/4501-1/https://github.com/LuaJIT/LuaJIT/issues/601https://lists.debian.org/debian-lts-announce/2020/07/msg00026.htmlhttps://lists.debian.org/debian-lts-announce/2025/08/msg00022.htmlhttps://usn.ubuntu.com/4501-1/
2020-07-21
Published