CVE-2024-25176

Name
CVE-2024-25176
Description
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gist.github.com/pwnhacker0x18/cd75d01fc7c9b6c85c183fbe5353d276
cve@mitre.org https://github.com/LuaJIT/LuaJIT/commit/343ce0edaf3906a62022936175b2f5410024cbfc
cve@mitre.org https://github.com/LuaJIT/LuaJIT/issues/1149
cve@mitre.org https://github.com/openresty/luajit2/commit/343ce0edaf3906a62022936175b2f5410024cbfc
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/08/msg00022.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
luajit edge-main 2.1_p20240815-r1 Jakub Jirutka <jakub@jirutka.cz> fixed
luajit edge-main 2.1_p20240815-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
luajit 3.22-main 2.1_p20240815-r1 Jakub Jirutka <jakub@jirutka.cz> fixed
luajit 3.21-main 2.1_p20240815-r1 None fixed
luajit 3.21-main 2.1_p20240815-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
luajit 3.20-main 2.1_p20240815-r1 None fixed
luajit 3.20-main 2.1_p20240314-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
luajit 3.19-main 2.1_p20240815-r1 None fixed
luajit 3.19-main 2.1_p20230410-r3 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable