Stack-based buffer overflow in Lua - CVE-2021-43519
Published: February 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the lua_resume() function of ldo.c. A remote attacker can pass a specially crafted script file to he application, trigger a stack-based buffer overflow and perform a denial of service (DoS) attack.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
lua (Red Hat package)
lua
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2021-43519
Red Hat OpenShift Container Platform - update to 4.13.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
lua (Red Hat package) - addressed in versions 5.4.4-1.el9_0.1, 5.4.4-2.el9_1
lua - addressed in versions 5.4.4-1.fc34, 5.4.4-1.fc35
External References
- http://lua-users.org/lists/lua-l/2021-11/msg00015.html
- http://lua-users.org/lists/lua-l/2021-10/msg00123.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C7XHFYHGSZKL53VCLSJSAJ6VMFGAIXKO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P3EMGAQ5Y6GXJLY4K5DUOOEQT4MZ4J4F/
Related Security Bulletins
- Denial of service in Lua interpreter
- Red Hat Enterprise Linux 9 update for lua
- Red Hat Enterprise Linux 9.0 Extended Update Support update for lua
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Fedora 35 update for lua
- Fedora 34 update for lua