yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-33099
Component Overview
Vulnerability Overview
Name
CVE-2022-33099
Source
NVD (
link
)
Debian (
link
)
Description
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
CWEs
CWE-787
Published Date
Jul 1, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/lua/lua/commit/42d40581dd919fb134c07027ca1ce0844c670daf
Patch
https://lua-users.org/lists/lua-l/2022-05/msg00035.html
Exploit
https://lua-users.org/lists/lua-l/2022-05/msg00042.html
Exploit
https://lua-users.org/lists/lua-l/2022-05/msg00073.html
Exploit
https://github.com/lua/lua/commit/42d40581dd919fb134c07027ca1ce0844c670daf
Patch
https://lua-users.org/lists/lua-l/2022-05/msg00035.html
Exploit
https://lua-users.org/lists/lua-l/2022-05/msg00042.html
Exploit
https://lua-users.org/lists/lua-l/2022-05/msg00073.html
Exploit
Analysis
#
Affected Component
Analysis
lua
Patched
Vulnerability Ratings
#
7.5
CVSSv31
5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
lua
buildroot
2025.02.x
5.1.5
Not Affected
lua
buildroot
master
5.1.5
Not Affected
lua
openwrt
master
5.1.5-r11
Not Affected
lua5.3
openwrt
master
5.3.5-r6
Not Affected
lua5.4
openwrt
master
5.4.7-r1
Not Affected
lua
openwrt
openwrt-25.12
5.1.5-r11
Not Affected
lua5.3
openwrt
openwrt-25.12
5.3.5-r6
Not Affected
lua5.4
openwrt
openwrt-25.12
5.4.7-r1
Not Affected
lua
yocto
master
5.5.0
Not Affected
lua
yocto
scarthgap
5.4.6
Not Affected
Resolved with patches
#
lua (yocto:kirkstone)
#
Title
Author
Resolve
1
Save stack space while handling errors
Roberto Ierusalimschy <roberto@inf.puc-rio.br>
CVE-2022-33099