Integer underflow in Lua - CVE-2020-24370
Published: August 17, 2020 / Updated: August 25, 2020
Vulnerability identifier: #VU45992
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24370
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
Affected software
Lua
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
zfs
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
SUSE MicroOS
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
lua (Red Hat package)
lua-help
lua-devel
lua
lua-debuginfo
lua-debugsource
liblua5_3-5
liblua5_3-5-32bit-debuginfo
liblua5_3-5-debuginfo
lua53-debuginfo
lua53-debugsource
lua53
liblua5_3-5-32bit
lua53-devel
syslinux-nonlinux
syslinux
syslinux-extlinux-nonlinux
syslinux-tftpboot
syslinux-debuginfo
syslinux-debugsource
syslinux-devel
syslinux-efi64
syslinux-extlinux
syslinux-perl
Red Hat OpenShift Serverless
OpenShift Virtualization
Dell EMC VxRail Appliance
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
zfs
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
SUSE MicroOS
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
lua (Red Hat package)
lua-help
lua-devel
lua
lua-debuginfo
lua-debugsource
liblua5_3-5
liblua5_3-5-32bit-debuginfo
liblua5_3-5-debuginfo
lua53-debuginfo
lua53-debugsource
lua53
liblua5_3-5-32bit
lua53-devel
syslinux-nonlinux
syslinux
syslinux-extlinux-nonlinux
syslinux-tftpboot
syslinux-debuginfo
syslinux-debugsource
syslinux-devel
syslinux-efi64
syslinux-extlinux
syslinux-perl
Red Hat OpenShift Serverless
OpenShift Virtualization
Dell EMC VxRail Appliance
How to mitigate CVE-2020-24370
Install update from vendor's website.
Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
zfs - update to 2.2.3
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
lua (Red Hat package) - update to 5.3.4-12.el8
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
OpenShift Virtualization - update to 4.11.0
lua-help - update to 5.3.5-5
lua-devel - update to 5.3.5-5
lua - update to 5.3.5-5
lua-debuginfo - update to 5.3.5-5
lua-debugsource - update to 5.3.5-5
lua - addressed in versions 5.3.5-8.fc31, 5.3.5-8.fc32
liblua5_3-5 - update to 5.3.6-3.6.1
liblua5_3-5-32bit-debuginfo - update to 5.3.6-3.6.1
liblua5_3-5-debuginfo - update to 5.3.6-3.6.1
lua53-debuginfo - update to 5.3.6-3.6.1
lua53-debugsource - update to 5.3.6-3.6.1
lua53 - update to 5.3.6-3.6.1
liblua5_3-5-32bit - update to 5.3.6-3.6.1
lua53-devel - update to 5.3.6-3.6.1
syslinux-nonlinux - addressed in versions 6.04-15, 6.04-17
syslinux - addressed in versions 6.04-15, 6.04-17
syslinux-extlinux-nonlinux - addressed in versions 6.04-15, 6.04-17
syslinux-tftpboot - addressed in versions 6.04-15, 6.04-17
syslinux-debuginfo - addressed in versions 6.04-15, 6.04-17
syslinux-debugsource - addressed in versions 6.04-15, 6.04-17
syslinux-devel - addressed in versions 6.04-15, 6.04-17
syslinux-efi64 - addressed in versions 6.04-15, 6.04-17
syslinux-extlinux - addressed in versions 6.04-15, 6.04-17
syslinux-perl - addressed in versions 6.04-15, 6.04-17
Dell EMC VxRail Appliance - update to 7.0.203
Red Hat OpenStack - update to 16.2
Cloud Pak for Security (CP4S) - update to 1.10.7.0
zfs - update to 2.2.3
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
lua (Red Hat package) - update to 5.3.4-12.el8
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
OpenShift Virtualization - update to 4.11.0
lua-help - update to 5.3.5-5
lua-devel - update to 5.3.5-5
lua - update to 5.3.5-5
lua-debuginfo - update to 5.3.5-5
lua-debugsource - update to 5.3.5-5
lua - addressed in versions 5.3.5-8.fc31, 5.3.5-8.fc32
liblua5_3-5 - update to 5.3.6-3.6.1
liblua5_3-5-32bit-debuginfo - update to 5.3.6-3.6.1
liblua5_3-5-debuginfo - update to 5.3.6-3.6.1
lua53-debuginfo - update to 5.3.6-3.6.1
lua53-debugsource - update to 5.3.6-3.6.1
lua53 - update to 5.3.6-3.6.1
liblua5_3-5-32bit - update to 5.3.6-3.6.1
lua53-devel - update to 5.3.6-3.6.1
syslinux-nonlinux - addressed in versions 6.04-15, 6.04-17
syslinux - addressed in versions 6.04-15, 6.04-17
syslinux-extlinux-nonlinux - addressed in versions 6.04-15, 6.04-17
syslinux-tftpboot - addressed in versions 6.04-15, 6.04-17
syslinux-debuginfo - addressed in versions 6.04-15, 6.04-17
syslinux-debugsource - addressed in versions 6.04-15, 6.04-17
syslinux-devel - addressed in versions 6.04-15, 6.04-17
syslinux-efi64 - addressed in versions 6.04-15, 6.04-17
syslinux-extlinux - addressed in versions 6.04-15, 6.04-17
syslinux-perl - addressed in versions 6.04-15, 6.04-17
Dell EMC VxRail Appliance - update to 7.0.203
Red Hat OpenStack - update to 16.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Lua
- Red Hat Enterprise Linux 8 update for lua
- SUSE update for lua53
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- zfs update for Lua
- openEuler 20.03 LTS SP4 update for lua
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.67
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1.20
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Migration Toolkit for Containers 1.5
- openEuler 22.03 LTS SP3 update for syslinux
- openEuler 22.03 LTS SP4 update for syslinux
- openEuler 24.03 LTS update for syslinux
- openEuler 24.03 LTS SP1 update for syslinux
- openEuler 20.03 LTS SP4 update for syslinux
- Fedora 32 update for lua
- Fedora 31 update for lua
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.2