CVE-2020-24370: Debian Linux
Medium severity, CVSS 5.3. EPSS: 3.8% chance of exploitation in the next 30 days.
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 31 only; version 32 only
- Lua Lua: version 5.2.0 only; version 5.2.1 only; version 5.2.2 only; version 5.2.3 only; version 5.3.0 only; version 5.3.1 only; …
Published 2020-08-17. Last modified 2026-06-17.