Logo
vulnerabilityCVE-2024-25177
Name
CVE-2024-25177
Source
NVD ( link)Debian ( link)
Description
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
luajit
Not Affected

Vulnerability Ratings#


7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
a4f56a459a588ae768801074b46ba0adcfb49eb1
Not Affected
buildroot
master
707c12bf00dafdfd3899b1a6c36435dbbf6c7022
Not Affected
openwrt
master
2.1.0-r8
Exploitable
openwrt
openwrt-25.12
2.1.0-r8
Exploitable
yocto
kirkstone
2.1.0~beta3-210112
Patched
yocto
scarthgap
2.1
Patched

Resolved with patches#


luajit (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix unsinking of IR_FSTORE for NULL metatable.
Changqing Li <changqing.li@windriver.com>
CVE-2024-25177

luajit (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix unsinking of IR_FSTORE for NULL metatable.
Changqing Li <changqing.li@windriver.com>
CVE-2024-25177