CVE-2020-24371 — Release of Invalid Pointer or Reference in Lua5.3
Severity
5.3MEDIUMNVD
EPSS
0.5%
top 35.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 17
Latest updateMay 24
Description
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4
Affected Packages6 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
3Microsoft▶
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.↗2020-08-11
Red Hat▶
lua: mishandles the interaction between barriers and the sweep phase leading to a memory access violation involving collectgarbage↗2020-07-15
Debian▶
CVE-2020-24371: lua5.3 - lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep pha...↗2020
💬Community
1Bugzilla▶
CVE-2020-24371 lua: mishandles the interaction between barriers and the sweep phase leading to a memory access violation involving collectgarbage↗2020-08-19