Bug 1174366 (CVE-2020-15890) - VUL-1: CVE-2020-15890: lua51-luajit: out-of-bounds read because __gc handler frame traversal is mishandled
Summary: VUL-1: CVE-2020-15890: lua51-luajit: out-of-bounds read because __gc handler ...
Status: RESOLVED FIXED
Alias: CVE-2020-15890
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.1
Hardware: Other Other
: P4 - Low : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/264075/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-07-22 06:33 UTC by Wolfgang Frisch
Modified: 2024-07-04 13:31 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-07-22 06:33:34 UTC
CVE-2020-15890

LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame
traversal is mishandled.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-15890
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15890
https://github.com/LuaJIT/LuaJIT/issues/601
Comment 1 Wolfgang Frisch 2024-07-04 13:31:15 UTC
The assignee has left the company.

Upstream fix:
https://github.com/LuaJIT/LuaJIT/commit/53f82e6e2e858a0a62fd1a2ff47e9866693382e6

Fixed in all supported codestreams.