Critical severity9.1NVD Advisory· Published Apr 8, 2022· Updated Jun 17, 2026
CVE-2022-28805
CVE-2022-28805
Description
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- osv-coords12 versionspkg:apk/chainguard/lua5.4pkg:apk/chainguard/lua5.4-devpkg:apk/chainguard/lua5.4-docpkg:apk/chainguard/lua5.4-libspkg:apk/wolfi/lua5.4pkg:apk/wolfi/lua5.4-devpkg:apk/wolfi/lua5.4-docpkg:apk/wolfi/lua5.4-libspkg:bitnami/luapkg:rpm/almalinux/luapkg:rpm/almalinux/lua-develpkg:rpm/almalinux/lua-libs
< 0+ 11 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: >= 5.4.0, < 5.4.5
- (no CPE)range: < 5.4.4-3.el9
- (no CPE)range: < 5.4.4-3.el9
- (no CPE)range: < 5.4.4-3.el9
Patches
Vulnerability mechanics
References
7- github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fanvdPatchThird Party Advisory
- lua-users.org/lists/lua-l/2022-02/msg00001.htmlnvdExploitMailing ListThird Party Advisory
- lua-users.org/lists/lua-l/2022-02/msg00070.htmlnvdExploitMailing ListThird Party Advisory
- lua-users.org/lists/lua-l/2022-04/msg00009.htmlnvdExploitMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHYZOEFDVLVAD6EEP4CDW6DNONIVVHPA/nvdThird Party Advisory
- security.gentoo.org/glsa/202305-23nvdThird Party Advisory
News mentions
0No linked articles in our index yet.