CVE-2020-24369: Lua

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.

Affected products

  • Lua Lua: version 5.4.0 only

Published 2020-08-17. Last modified 2026-06-17.