CVE-2020-24371: Lua

Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.

lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.

Affected products

  • Lua Lua: version 5.4.0 only

Published 2020-08-17. Last modified 2026-06-17.