CVE-2021-43519
published 2021-11-09CVE-2021-43519: Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.14%
62.9th percentile
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lua5.1 | < lua5.4 5.4.4-1 (bookworm) | lua5.4 5.4.4-1 (bookworm) |
| debian | lua5.2 | < lua5.4 5.4.4-1 (bookworm) | lua5.4 5.4.4-1 (bookworm) |
| debian | lua5.3 | < lua5.4 5.4.4-1 (bookworm) | lua5.4 5.4.4-1 (bookworm) |
| debian | lua5.4 | < lua5.4 5.4.4-1 (bookworm) | lua5.4 5.4.4-1 (bookworm) |
| debian | lua50 | < lua5.4 5.4.4-1 (bookworm) | lua5.4 5.4.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| lua | lua | >= 5.1.0 < 5.3.5 | 5.3.5 |
| lua | lua | >= 5.4.0 < 5.4.4 | 5.4.4 |
| msrc | azl3_ceph_18.2.2-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_lua_5.4.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_lua_5.4.6-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_memcached_1.6.27-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_memcached_1.6.27-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_ntopng_5.2.1-5_on_azure_linux_3.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
vendor_msrc·2021-11-09·CVSS 5.5
CVE-2021-43519 [MEDIUM] CWE-674 Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Cu
Red Hat
lua: stack overflow in lua_resume of ldo.c allows a DoS via a crafted script file
vendor_redhat·2021-11-09·CVSS 5.5
CVE-2021-43519 [MEDIUM] CWE-787 lua: stack overflow in lua_resume of ldo.c allows a DoS via a crafted script file
lua: stack overflow in lua_resume of ldo.c allows a DoS via a crafted script file
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
A stack overflow issue was discovered in Lua in the lua_resume() function of 'ldo.c'. This flaw allows a local attacker to pass a specially crafted file to the Lua Interpreter, causing a crash that leads to a denial of service.
Statement: This vulnerability does not affect Red Hat Enterprise Linux 8, because code-base was completely rewritten between 5.3 and 5.4. So, RHEL-8 is unlikely to be affected by this or a similar issue.
This flaw is marked as Out-of-Support-Scope for Red Hat Enterprise Linux 6 and 7 because the flaw impact is moderate. For additional inform
Debian
CVE-2021-43519: lua5.1 - Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows atta...
vendor_debian·2021·CVSS 5.5
CVE-2021-43519 [MEDIUM] CVE-2021-43519: lua5.1 - Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows atta...
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-g78p-3v3v-h7wm: Stack overflow in lua_resume of ldo
ghsa_unreviewed·2022-05-24
CVE-2021-43519 [MEDIUM] CWE-674 GHSA-g78p-3v3v-h7wm: Stack overflow in lua_resume of ldo
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
OSV
CVE-2021-43519: Stack overflow in lua_resume of ldo
osv·2021-11-09·CVSS 5.5
CVE-2021-43519 [MEDIUM] CVE-2021-43519: Stack overflow in lua_resume of ldo
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lua-users.org/lists/lua-l/2021-10/msg00123.htmlhttp://lua-users.org/lists/lua-l/2021-11/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C7XHFYHGSZKL53VCLSJSAJ6VMFGAIXKO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3EMGAQ5Y6GXJLY4K5DUOOEQT4MZ4J4F/http://lua-users.org/lists/lua-l/2021-10/msg00123.htmlhttp://lua-users.org/lists/lua-l/2021-11/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C7XHFYHGSZKL53VCLSJSAJ6VMFGAIXKO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P3EMGAQ5Y6GXJLY4K5DUOOEQT4MZ4J4F/
2021-11-09
Published