Name
CVE-2019-6706
Description
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/security/cve/cve-2019-6706Third Party Advisory
https://access.redhat.com/security/cve/cve-2019-6706Third Party Advisory
Analysis#
Vulnerability Ratings#
7.5
CVSSv31
5
CVSSv2
Others affected components#
Name
Project
Project Version
Version
Status
buildroot
2025.02.x
5.1.5
Not Affected
buildroot
master
5.1.5
Not Affected
openwrt
openwrt-25.12
5.1.5-r11
Patched
openwrt
openwrt-25.12
5.3.5-r6
Patched
openwrt
openwrt-25.12
5.4.7-r1
Patched
yocto
kirkstone
5.4.4
Not Affected
yocto
master
5.5.0
Not Affected
yocto
scarthgap
5.4.6
Not Affected
Resolved with patches#
lua5.3 (openwrt:master)
#
Title
Author
Resolve
1
Fixed bug in 'lua_upvaluejoin'
Roberto Ierusalimschy <roberto@inf.puc-rio.br>
CVE-2019-6706
lua5.3 (openwrt:openwrt-25.12)
#
Title
Author
Resolve
1
Fixed bug in 'lua_upvaluejoin'
Roberto Ierusalimschy <roberto@inf.puc-rio.br>
CVE-2019-6706