yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-25178
Component Overview
Vulnerability Overview
Name
CVE-2024-25178
Source
NVD (
link
)
Debian (
link
)
Description
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
CWEs
CWE-125
Published Date
Jul 7, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://gist.github.com/pwnhacker0x18/423b4292f301ab274b42d5ed6e0b87d8
Third Party Advisory
https://github.com/LuaJIT/LuaJIT/commit/defe61a56751a0db5f00ff3ab7b8f45436ba74c8
Patch
https://github.com/LuaJIT/LuaJIT/issues/1152
Exploit
https://github.com/LuaJIT/LuaJIT/issues/1152
Exploit
Analysis
#
Affected Component
Analysis
luajit
Patched
Vulnerability Ratings
#
9.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
luajit
buildroot
2025.02.x
a4f56a459a588ae768801074b46ba0adcfb49eb1
Not Affected
luajit
buildroot
master
707c12bf00dafdfd3899b1a6c36435dbbf6c7022
Not Affected
luajit
openwrt
master
2.1.0-r8
Exploitable
luajit
openwrt
openwrt-25.12
2.1.0-r8
Exploitable
luajit
yocto
kirkstone
2.1.0~beta3-210112
Patched
luajit
yocto
master
2.1
Not Affected
Resolved with patches
#
luajit (yocto:kirkstone)
#
Title
Author
Resolve
1
Rework stack overflow handling.
Mike Pall <mike>
CVE-2024-25178
luajit (yocto:scarthgap)
#
Title
Author
Resolve
1
Rework stack overflow handling.
Mike Pall <mike>
CVE-2024-25178