PT-2022-23076 · Minetest+2 · Minetest+2

Highsfan5

·

Published

2022-08-06

·

Updated

2025-02-20

·

CVE-2022-35978

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Minetest versions prior to 5.6.1
Description The issue concerns a security vulnerability in Minetest, a free open-source voxel game engine, where a mod in single-player mode can set a global setting to control the Lua script loaded for the main menu. This script is loaded upon exiting the game session, and since the Lua environment is not sandboxed, it can directly interfere with the user's system. There are currently no known workarounds for this issue.
Recommendations For versions prior to 5.6.1, update to version 5.6.1 to resolve the issue. As a temporary workaround, consider disabling the use of mods in single-player mode until the update can be applied. Restrict access to the Lua script loaded for the main menu to minimize the risk of exploitation. Avoid using mods that could potentially set malicious global settings for the main menu script.

Exploit

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2357
ALT-PU-2022-2540
CVE-2022-35978
GHSA-663Q-PCJW-27CC
MGASA-2023-0005
OPENSUSE-SU-2023:0001-1
OPENSUSE-SU-2024:12284-1
OPENSUSE-SU-2025:14825-1

Affected Products

Alt Linux
Debian
Minetest