PT-2024-24080 · Lua+1 · Lua+2

Caeleron

·

Published

2024-04-16

·

Updated

2024-04-17

·

CVE-2024-31446

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenComputers versions prior to 1.8.4 GregTech: New Horizons modpack versions prior to 1.10.10-GTNH
Description The issue allows a user to get a Computer thread stuck in the Lua VM, which eventually blocks the Server thread, requiring the server to be forcibly shut down. This can be accomplished using any device in the mod and can be performed by anyone who can execute Lua code on them. The problem occurs while using the native Lua library, but LuaJ appears to not have this issue.
Recommendations For OpenComputers versions prior to 1.8.4, update to version 1.8.4 to resolve the issue. For GregTech: New Horizons modpack versions prior to 1.10.10-GTNH, update to version 1.10.10-GTNH to apply the relevant patch. As a temporary workaround, consider restricting the execution of Lua code on devices in the mod to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-31446
GHSA-54J4-XPGJ-CQ4G

Affected Products

Gregtech: New Horizons
Lua
Opencomputers