PT-2024-24080 · Lua+1 · Lua+2
Caeleron
·
Published
2024-04-16
·
Updated
2024-04-17
·
CVE-2024-31446
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenComputers versions prior to 1.8.4
GregTech: New Horizons modpack versions prior to 1.10.10-GTNH
Description
The issue allows a user to get a Computer thread stuck in the Lua VM, which eventually blocks the Server thread, requiring the server to be forcibly shut down. This can be accomplished using any device in the mod and can be performed by anyone who can execute Lua code on them. The problem occurs while using the native Lua library, but LuaJ appears to not have this issue.
Recommendations
For OpenComputers versions prior to 1.8.4, update to version 1.8.4 to resolve the issue.
For GregTech: New Horizons modpack versions prior to 1.10.10-GTNH, update to version 1.10.10-GTNH to apply the relevant patch.
As a temporary workaround, consider restricting the execution of Lua code on devices in the mod to minimize the risk of exploitation.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gregtech: New Horizons
Lua
Opencomputers