Out-of-bounds read in radare2 - #VU142708
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the Lua 5.3 bytecode function parser when parsing a crafted Lua 5.3 bytecode file. A remote attacker can trick the victim into opening or inspecting a crafted file to cause a denial of service.
No attacker-observable memory disclosure has been demonstrated.