PT-2025-28210 · Luajit+2 · Luajit+2

Published

2025-07-07

·

Updated

2025-09-26

·

CVE-2024-25176

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: LuaJIT versions 2.1 and earlier
Description: The issue is related to a stack-buffer-overflow in the lj strfmt wfnum function located in lj strfmt num.c. This overflow can potentially lead to exploitation. No information is provided about the estimated number of affected devices or real-world incidents.
Recommendations: For LuaJIT versions 2.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Stack Overflow

Weakness Enumeration

Related Identifiers

AZL-65370
AZL-65394
AZL-65427
CVE-2024-25176
DLA-4283-1
ECHO-0C63-8FB4-89C9
SUSE-SU-2025:02886-1
SUSE-SU-2025:03378-1
SUSE-SU-2025_03378-1

Affected Products

Debian
Luajit
Suse