CVE-2024-25176
Published: July 10, 2025Last modified: September 26, 2025
Description
LuaJIT through 2.1 has a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 9.8 |
| Attack Vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity impact | HIGH |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | luajit | Fixed (2.1_p20210510-r4) |
| Stream | luajit | Fixed (2.1_p20240314-r0) |
References
- https://gist.github.com/pwnhacker0x18/cd75d01fc7c9b6c85c183fbe5353d276
- https://github.com/LuaJIT/LuaJIT/commit/343ce0edaf3906a62022936175b2f5410024cbfc
- https://github.com/LuaJIT/LuaJIT/issues/1149
- https://github.com/openresty/luajit2/commit/343ce0edaf3906a62022936175b2f5410024cbfc
- https://lists.debian.org/debian-lts-announce/2025/08/msg00022.html