Related Vulnerabilities: CVE-2022-33099  

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

Description

The MITRE CVE dictionary describes this issue as:

An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

Additional Information

  • Bugzilla 2104427: CVE-2022-33099 lua: heap buffer overflow in luaG_errormsg() in ldebug.c due to uncontrolled recursion in error handling
  • FAQ: Frequently asked questions about CVE-2022-33099