High severity7.5NVD Advisory· Published Jul 1, 2022· Updated Jun 17, 2026
CVE-2022-33099
CVE-2022-33099
Description
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- osv-coords5 versionspkg:bitnami/luapkg:rpm/almalinux/luapkg:rpm/almalinux/lua-develpkg:rpm/almalinux/lua-libspkg:rpm/opensuse/lua55&distro=openSUSE%20Tumbleweed
>= 5.4.2, < 5.4.5+ 4 more
- (no CPE)range: >= 5.4.2, < 5.4.5
- (no CPE)range: < 5.4.2-4.el9_0.3
- (no CPE)range: < 5.4.2-4.el9_0.3
- (no CPE)range: < 5.4.2-4.el9_0.3
- (no CPE)range: < 5.5.0~beta1-1.1
Patches
Vulnerability mechanics
References
7- github.com/lua/lua/commit/42d40581dd919fb134c07027ca1ce0844c670dafnvdPatchThird Party Advisory
- lua-users.org/lists/lua-l/2022-05/msg00035.htmlnvdExploitMailing ListVendor Advisory
- lua-users.org/lists/lua-l/2022-05/msg00042.htmlnvdExploitMailing ListVendor Advisory
- lua-users.org/lists/lua-l/2022-05/msg00073.htmlnvdExploitMailing ListVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RJNJ66IFDUKWJJZXHGOLRGIA3HWWC36R/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHYZOEFDVLVAD6EEP4CDW6DNONIVVHPA/nvd
- www.lua.org/bugs.htmlnvd
News mentions
0No linked articles in our index yet.