yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-25176
Component Overview
Vulnerability Overview
Name
CVE-2024-25176
Source
NVD (
link
)
Debian (
link
)
Description
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
CWEs
CWE-121
Published Date
Jul 7, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gist.github.com/pwnhacker0x18/cd75d01fc7c9b6c85c183fbe5353d276
Third Party Advisory
https://github.com/LuaJIT/LuaJIT/commit/343ce0edaf3906a62022936175b2f5410024cbfc
Patch
https://github.com/LuaJIT/LuaJIT/issues/1149
Exploit
https://github.com/LuaJIT/LuaJIT/issues/1149
Exploit
Analysis
#
Affected Component
Analysis
luajit
Patched
Vulnerability Ratings
#
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
luajit
buildroot
2025.02.x
a4f56a459a588ae768801074b46ba0adcfb49eb1
Not Affected
luajit
buildroot
master
707c12bf00dafdfd3899b1a6c36435dbbf6c7022
Not Affected
luajit
openwrt
master
2.1.0-r8
Exploitable
luajit
openwrt
openwrt-25.12
2.1.0-r8
Exploitable
luajit
yocto
kirkstone
2.1.0~beta3-210112
Patched
luajit
yocto
master
2.1
Not Affected
Resolved with patches
#
luajit (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix zero stripping in %g number formatting.
Changqing Li <changqing.li@windriver.com>
CVE-2024-25176
luajit (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix zero stripping in %g number formatting.
Mike Pall <mike>
CVE-2024-25176