CVE-2020-24371Release of Invalid Pointer or Reference in Lua5.3

Severity
5.3MEDIUMNVD
EPSS
0.5%
top 35.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 24

Description

lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages6 packages

debiandebian/lua5.3< lua5.4 5.4.1-1 (bookworm)
debiandebian/lua5.4< lua5.4 5.4.1-1 (bookworm)
NVDlua/lua5.4.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4m5p-2hm8-9fxm: lgc2022-05-24
OSV
CVE-2020-24371: lgc2020-08-17

📋Vendor Advisories

3
Microsoft
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.2020-08-11
Red Hat
lua: mishandles the interaction between barriers and the sweep phase leading to a memory access violation involving collectgarbage2020-07-15
Debian
CVE-2020-24371: lua5.3 - lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep pha...2020

💬Community

1
Bugzilla
CVE-2020-24371 lua: mishandles the interaction between barriers and the sweep phase leading to a memory access violation involving collectgarbage2020-08-19
CVE-2020-24371 — Debian Lua5.3 vulnerability | cvebase