yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-28805
Component Overview
Vulnerability Overview
Name
CVE-2022-28805
Source
NVD (
link
)
Debian (
link
)
Description
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
CWEs
CWE-125
Published Date
Apr 8, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fa
Patch
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHYZOEFDVLVAD6EEP4CDW6DNONIVVHPA/
Third Party Advisory
https://lua-users.org/lists/lua-l/2022-02/msg00001.html
Exploit
https://lua-users.org/lists/lua-l/2022-02/msg00070.html
Exploit
https://lua-users.org/lists/lua-l/2022-04/msg00009.html
Exploit
https://security.gentoo.org/glsa/202305-23
Third Party Advisory
https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fa
Patch
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHYZOEFDVLVAD6EEP4CDW6DNONIVVHPA/
Third Party Advisory
https://lua-users.org/lists/lua-l/2022-02/msg00001.html
Exploit
https://lua-users.org/lists/lua-l/2022-02/msg00070.html
Exploit
https://lua-users.org/lists/lua-l/2022-04/msg00009.html
Exploit
https://security.gentoo.org/glsa/202305-23
Third Party Advisory
Analysis
#
Affected Component
Analysis
lua
Patched
Vulnerability Ratings
#
9.1
CVSSv31
6.4
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
lua
buildroot
2025.02.x
5.1.5
Not Affected
lua
buildroot
master
5.1.5
Not Affected
lua
openwrt
master
5.1.5-r11
Not Affected
lua5.3
openwrt
master
5.3.5-r6
Not Affected
lua5.4
openwrt
master
5.4.7-r1
Not Affected
lua
openwrt
openwrt-25.12
5.1.5-r11
Not Affected
lua5.3
openwrt
openwrt-25.12
5.3.5-r6
Not Affected
lua5.4
openwrt
openwrt-25.12
5.4.7-r1
Not Affected
lua
yocto
master
5.5.0
Not Affected
lua
yocto
scarthgap
5.4.6
Not Affected
Resolved with patches
#
lua (yocto:kirkstone)
#
Title
Author
Resolve
1
Bug: Lua can generate wrong code when _ENV is <const>
Roberto Ierusalimschy <roberto@inf.puc-rio.br>
CVE-2022-28805