PT-2020-14689 · Lua · Lua

·

CVE-2020-15888

·

Published

2020-07-21

·

Updated

2025-08-03

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lua versions prior to 5.4.0
Description The issue is related to how Lua handles the interaction between stack resizes and garbage collection, leading to potential heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
Recommendations For versions prior to 5.4.0, update to version 5.4.0 or later to resolve the issue.

Exploit

Fix

DoS

Use After Free

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-6670
BIT-LUA-2020-15888
CVE-2020-15888
OPENSUSE-SU-2024:11029-1
OPENSUSE-SU-2025:15401-1

Affected Products

Lua