CVE-2024-25178

Name
CVE-2024-25178
Description
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gist.github.com/pwnhacker0x18/423b4292f301ab274b42d5ed6e0b87d8
cve@mitre.org https://github.com/LuaJIT/LuaJIT/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8
cve@mitre.org https://github.com/LuaJIT/LuaJIT/issues/1152
cve@mitre.org https://github.com/openresty/luajit2/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/08/msg00022.html

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
luajit edge-main 2.1_p20240815-r1 Jakub Jirutka <jakub@jirutka.cz> fixed
luajit edge-main 2.1_p20240815-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
luajit 3.22-main 2.1_p20240815-r1 Jakub Jirutka <jakub@jirutka.cz> fixed
luajit 3.21-main 2.1_p20240815-r1 None fixed
luajit 3.21-main 2.1_p20240815-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
luajit 3.20-main 2.1_p20240815-r1 None fixed
luajit 3.20-main 2.1_p20240314-r0 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable
luajit 3.19-main 2.1_p20240815-r1 None fixed
luajit 3.19-main 2.1_p20230410-r3 Jakub Jirutka <jakub@jirutka.cz> possibly vulnerable