PT-2022-12190 · Lua+1 · Lua+1

Kang Woosun

·

Published

2022-01-11

·

Updated

2025-08-03

·

CVE-2021-44647

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Lua versions 5.4.2 through 5.4.4
Description The issue is related to a type confusion in the funcnamefromcode function in ldebug.c, which can cause a local denial of service due to a SEGV.
Recommendations For Lua versions 5.4.2 through 5.4.4, consider disabling the funcnamefromcode function in ldebug.c as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Type Confusion

Weakness Enumeration

Related Identifiers

AZL-41327
AZL-41797
AZL-9317
BIT-LUA-2021-44647
CVE-2021-44647
OESA-2022-1632
OPENSUSE-SU-2024:12156-1
OPENSUSE-SU-2025:15401-1

Affected Products

Debian
Lua