Severity
7.5HIGHNVD
EPSS
0.3%
top 50.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateApr 11

Description

In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages18 packages

NVDlua/lua5.4.05.4.4
debiandebian/lua50< lua5.4 5.4.4-1 (bookworm)
debiandebian/lua5.1< lua5.4 5.4.4-1 (bookworm)
debiandebian/lua5.2< lua5.4 5.4.4-1 (bookworm)
debiandebian/lua5.3< lua5.4 5.4.4-1 (bookworm)

Patches

🔴Vulnerability Details

2
OSV
CVE-2021-45985: In Lua 52023-04-10
GHSA
GHSA-pxvf-cp3x-784h: In Lua 52023-04-10

📋Vendor Advisories

3
Microsoft
Mitre: CVE-2021-45985 Erroneous finalizer call in Lua leads to a heap-based buffer over-read2023-04-11
Red Hat
lua: heap-based buffer over-read2023-04-10
Debian
CVE-2021-45985: lua5.1 - In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-b...2021
CVE-2021-45985 — Out-of-bounds Write in LUA | cvebase