CVE-2022-28805
published 2022-04-08CVE-2022-28805: singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read…
PriorityP346critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
3.00%
86.0th percentile
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lua5.1 | < lua5.4 5.4.4-2 (bookworm) | lua5.4 5.4.4-2 (bookworm) |
| debian | lua5.2 | < lua5.4 5.4.4-2 (bookworm) | lua5.4 5.4.4-2 (bookworm) |
| debian | lua5.3 | < lua5.4 5.4.4-2 (bookworm) | lua5.4 5.4.4-2 (bookworm) |
| debian | lua5.4 | < lua5.4 5.4.4-2 (bookworm) | lua5.4 5.4.4-2 (bookworm) |
| debian | lua50 | < lua5.4 5.4.4-2 (bookworm) | lua5.4 5.4.4-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| lua | lua | >= 5.4.0 < 5.4.5 | 5.4.5 |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_memcached_1.6.27-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_ntopng_5.2.1-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_ntopng_5.2.1-5_on_azure_linux_3.0 | — | — |
| msrc | cbl2_lua_5.4.3-2_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_lua_5.3.5-9_on_cbl_mariner_1.0 | — | — |
| msrc | lua-5.3.5-9.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | lua-5.3.5-9.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | lua-5.4.3-2.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | lua-5.4.3-2.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | lua-debuginfo-5.3.5-9.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | lua-debuginfo-5.3.5-9.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | lua-debuginfo-5.4.3-2.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
| msrc | lua-debuginfo-5.4.3-2.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64 | — | — |
| msrc | lua-devel-5.3.5-9.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm | — | — |
| msrc | lua-devel-5.3.5-9.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64 | — | — |
| msrc | lua-devel-5.4.3-2.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian9.1LOW
vendor_msrc9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Lua vulnerabilities
vendor_ubuntu·2024-07-29·CVSS 9.1
CVE-2022-33099 [CRITICAL] Lua vulnerabilities
Title: Lua vulnerabilities
Summary: Several security issues were fixed in Lua.
It was discovered that Lua did not properly generate code when "_ENV" is
constant. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary unstrusted lua code. (CVE-2022-28805)
It was discovered that Lua did not properly handle C stack overflows during
error handling. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-33099)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call leading to a heap-based buffer over-read that might affect a system that compiles un
vendor_msrc·2022-04-12·CVSS 9.1
CVE-2022-28805 [CRITICAL] CWE-125 singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call leading to a heap-based buffer over-read that might affect a system that compiles un
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, w
Red Hat
lua: heap buffer overread
vendor_redhat·2022-04-08·CVSS 9.1
CVE-2022-28805 [CRITICAL] CWE-125 lua: heap buffer overread
lua: heap buffer overread
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
A heap buffer-overflow vulnerability was found in Lua. The flaw occurs due to vulnerable code present in the lparser.c function of Lua that allows the execution of untrusted Lua code into a system, resulting in malicious activity.
Package: lua (Red Hat Enterprise Linux 6) - Not affected
Package: lua (Red Hat Enterprise Linux 7) - Not affected
Package: libreoffice:flatpak/lua (Red Hat Enterprise Linux 8) - Not affected
Package: lua (Red Hat Enterprise Linux 8) - Not affected
Package: lua (Red Hat JBoss Core Services) - Not affected
Debian
CVE-2022-28805: lua5.1 - singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lac...
vendor_debian·2022·CVSS 9.1
CVE-2022-28805 [CRITICAL] CVE-2022-28805: lua5.1 - singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lac...
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
lua5.4 vulnerabilities
osv·2024-07-29·CVSS 9.1
CVE-2022-28805 [CRITICAL] lua5.4 vulnerabilities
lua5.4 vulnerabilities
It was discovered that Lua did not properly generate code when "_ENV" is
constant. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary unstrusted lua code. (CVE-2022-28805)
It was discovered that Lua did not properly handle C stack overflows during
error handling. An attacker could possibly use this issue to cause a denial
of service. (CVE-2022-33099)
GHSA
GHSA-pxhp-rhgc-5jx8: singlevar in lparser
ghsa_unreviewed·2022-04-09
CVE-2022-28805 [CRITICAL] CWE-125 GHSA-pxhp-rhgc-5jx8: singlevar in lparser
singlevar in lparser.c in Lua through 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
OSV
CVE-2022-28805: singlevar in lparser
osv·2022-04-08·CVSS 9.1
CVE-2022-28805 [CRITICAL] CVE-2022-28805: singlevar in lparser
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHYZOEFDVLVAD6EEP4CDW6DNONIVVHPA/https://lua-users.org/lists/lua-l/2022-02/msg00001.htmlhttps://lua-users.org/lists/lua-l/2022-02/msg00070.htmlhttps://lua-users.org/lists/lua-l/2022-04/msg00009.htmlhttps://security.gentoo.org/glsa/202305-23https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fahttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHYZOEFDVLVAD6EEP4CDW6DNONIVVHPA/https://lua-users.org/lists/lua-l/2022-02/msg00001.htmlhttps://lua-users.org/lists/lua-l/2022-02/msg00070.htmlhttps://lua-users.org/lists/lua-l/2022-04/msg00009.htmlhttps://security.gentoo.org/glsa/202305-23
2022-04-08
Published