PT-2020-14689 · Lua · Lua

Roberto-Ieru

·

Published

2020-07-21

·

Updated

2025-08-03

·

CVE-2020-15888

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lua versions prior to 5.4.0
Description The issue is related to how Lua handles the interaction between stack resizes and garbage collection, leading to potential heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
Recommendations For versions prior to 5.4.0, update to version 5.4.0 or later to resolve the issue.

Exploit

Fix

Out of bounds Read

Use After Free

Memory Corruption

Weakness Enumeration

Related Identifiers

AZL-6670
BIT-LUA-2020-15888
CVE-2020-15888
OPENSUSE-SU-2024:11029-1
OPENSUSE-SU-2025:15401-1

Affected Products

Lua