Lua · Lua · CVE-2026-24028
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
An attacker can trigger an out-of-bounds read by sending a crafted DNS response packet when custom Lua code utilizes the `newDNSPacketOverlay()` function to parse DNS packets. This out-of-bounds read may result in a system crash, causing a denial of service, or allow access to unrelated memory, potentially leading to information disclosure.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.