Heap use-after-free in Lua - CVE-2019-6706
Published: January 27, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a geap use-after-free error in lua_upvaluejoin in lapi.c. A remote attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships can cause the service to crash.
Affected software
lua5.3 (Ubuntu package)
lua5.3 (Alpine package)
lua
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Dell PowerProtect Cyber Recovery
How to mitigate CVE-2019-6706
lua5.3 (Alpine package) - addressed in versions 5.3.5-r0, 5.3.5-r1
lua - update to 5.3.5-3.fc29
Dell PowerProtect Cyber Recovery - update to 18.1.1.2-8