Integer underflow in Lua - CVE-2020-24370

 

Integer underflow in Lua - CVE-2020-24370

Published: August 17, 2020 / Updated: August 25, 2020


Vulnerability identifier: #VU45992
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24370
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).


Affected software

Lua
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
zfs
Ansible Automation Platform
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Red Hat OpenStack
SUSE MicroOS
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Module for Basesystem
openEuler
Fedora
lua (Red Hat package)
lua-help
lua-devel
lua
lua-debuginfo
lua-debugsource
liblua5_3-5
liblua5_3-5-32bit-debuginfo
liblua5_3-5-debuginfo
lua53-debuginfo
lua53-debugsource
lua53
liblua5_3-5-32bit
lua53-devel
syslinux-nonlinux
syslinux
syslinux-extlinux-nonlinux
syslinux-tftpboot
syslinux-debuginfo
syslinux-debugsource
syslinux-devel
syslinux-efi64
syslinux-extlinux
syslinux-perl
Red Hat OpenShift Serverless
OpenShift Virtualization
Dell EMC VxRail Appliance

How to mitigate CVE-2020-24370

Install update from vendor's website.

Migration Toolkit for Containers - addressed in versions 1.5.4, 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
zfs - update to 2.2.3
Red Hat OpenShift Container Platform - addressed in versions 4.11.0, 4.11.45
lua (Red Hat package) - update to 5.3.4-12.el8
Red Hat OpenShift Serverless - update to 1.20.0
Red Hat Advanced Cluster Management for Kubernetes - update to 2.2.10
Red Hat Advanced Cluster Security for Kubernetes - update to 3.67
OpenShift Virtualization - update to 4.11.0
lua-help - update to 5.3.5-5
lua-devel - update to 5.3.5-5
lua - update to 5.3.5-5
lua-debuginfo - update to 5.3.5-5
lua-debugsource - update to 5.3.5-5
lua - addressed in versions 5.3.5-8.fc31, 5.3.5-8.fc32
liblua5_3-5 - update to 5.3.6-3.6.1
liblua5_3-5-32bit-debuginfo - update to 5.3.6-3.6.1
liblua5_3-5-debuginfo - update to 5.3.6-3.6.1
lua53-debuginfo - update to 5.3.6-3.6.1
lua53-debugsource - update to 5.3.6-3.6.1
lua53 - update to 5.3.6-3.6.1
liblua5_3-5-32bit - update to 5.3.6-3.6.1
lua53-devel - update to 5.3.6-3.6.1
syslinux-nonlinux - addressed in versions 6.04-15, 6.04-17
syslinux - addressed in versions 6.04-15, 6.04-17
syslinux-extlinux-nonlinux - addressed in versions 6.04-15, 6.04-17
syslinux-tftpboot - addressed in versions 6.04-15, 6.04-17
syslinux-debuginfo - addressed in versions 6.04-15, 6.04-17
syslinux-debugsource - addressed in versions 6.04-15, 6.04-17
syslinux-devel - addressed in versions 6.04-15, 6.04-17
syslinux-efi64 - addressed in versions 6.04-15, 6.04-17
syslinux-extlinux - addressed in versions 6.04-15, 6.04-17
syslinux-perl - addressed in versions 6.04-15, 6.04-17
Dell EMC VxRail Appliance - update to 7.0.203
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins