Medium severity5.3NVD Advisory· Published Aug 17, 2020· Updated Jun 17, 2026
CVE-2020-24370
CVE-2020-24370
Description
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
32cpe:2.3:a:lua:lua:5.2.0:-:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:lua:lua:5.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.2.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.2.0:beta:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.0:-:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.0:beta:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.1:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.2:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.4:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.4.0:-:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.4.0:alpha:*:*:*:*:*:*
- cpe:2.3:a:lua:lua:5.4.0:beta:*:*:*:*:*:*
- (no CPE)range: = 5.4.0
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- (empty string)/Luadescription
- osv-coords10 versionspkg:bitnami/luapkg:rpm/almalinux/luapkg:rpm/almalinux/lua-develpkg:rpm/almalinux/lua-libspkg:rpm/opensuse/lua53&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/lua53&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/lua55&distro=openSUSE%20Tumbleweedpkg:rpm/suse/lua53&distro=SUSE%20Linux%20Enterprise%20Micro%205.0pkg:rpm/suse/lua53&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/lua53&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
>= 5.2.0, < 5.2.4+ 9 more
- (no CPE)range: >= 5.2.0, < 5.2.4
- (no CPE)range: < 5.3.4-12.el8
- (no CPE)range: < 5.3.4-12.el8
- (no CPE)range: < 5.3.4-12.el8
- (no CPE)range: < 5.3.6-lp152.5.3.1
- (no CPE)range: < 5.3.6-3.6.1
- (no CPE)range: < 5.5.0~beta1-1.1
- (no CPE)range: < 5.3.6-3.6.1
- (no CPE)range: < 5.3.6-3.6.1
- (no CPE)range: < 5.3.6-3.6.1
Patches
Vulnerability mechanics
References
6- github.com/lua/lua/commit/a585eae6e7ada1ca9271607a4f48dfb17868ab7bnvdPatchThird Party Advisory
- lua-users.org/lists/lua-l/2020-07/msg00324.htmlnvdExploitMailing ListVendor Advisory
- lists.debian.org/debian-lts-announce/2020/09/msg00019.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/06/msg00031.htmlnvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E6KONNG6UEI3FMEOY67NDZC32NBGBI44/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QXYMCIUNGK26VHAYHGP5LPW56G2KWOHQ/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.