CVE-2024-25177
Published: July 10, 2025Last modified: September 26, 2025
Description
LuaJIT through 2.1 has an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 7.5 |
| Attack Vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | NONE |
| Integrity impact | NONE |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | luajit | Fixed (2.1_p20210510-r4) |
| Stream | luajit | Fixed (2.1_p20240314-r0) |
References
- https://gist.github.com/pwnhacker0x18/a73f560d79f2c3d4011d6c5a2676f04a
- https://github.com/LuaJIT/LuaJIT/commit/85b4fed0b0353dd78c8c875c2f562d522a2b310f
- https://github.com/LuaJIT/LuaJIT/issues/1147
- https://github.com/openresty/luajit2/commit/85b4fed0b0353dd78c8c875c2f562d522a2b310f
- https://lists.debian.org/debian-lts-announce/2025/08/msg00022.html