CVE-2024-25178

LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:luajit:luajit:*:*:*:*:*:*:*:*

History

24 Jul 2025, 16:15

Type Values Removed Values Added
Summary (en) LuaJIT through 2.1 has an out-of-bounds read in the stack-overflow handler in lj_state.c (en) LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
References
  • () https://github.com/openresty/luajit2/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8 -

17 Jul 2025, 16:01

Type Values Removed Values Added
CPE cpe:2.3:a:luajit:luajit:*:*:*:*:*:*:*:*
References () https://gist.github.com/pwnhacker0x18/423b4292f301ab274b42d5ed6e0b87d8 - () https://gist.github.com/pwnhacker0x18/423b4292f301ab274b42d5ed6e0b87d8 - Third Party Advisory
References () https://github.com/LuaJIT/LuaJIT/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8 - () https://github.com/LuaJIT/LuaJIT/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8 - Patch
References () https://github.com/LuaJIT/LuaJIT/issues/1152 - () https://github.com/LuaJIT/LuaJIT/issues/1152 - Exploit, Issue Tracking
First Time Luajit luajit
Luajit

08 Jul 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 17:15

Updated : 2025-07-24 16:15


NVD link : CVE-2024-25178

Mitre link : CVE-2024-25178

CVE.ORG link : CVE-2024-25178


JSON object : View

Products Affected

luajit

  • luajit
CWE
CWE-125

Out-of-bounds Read