CVE-2020-24372: Luajit

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.

Affected products

  • Luajit Luajit: up to and including 2.0.5; version 2.1.0 only

Published 2020-08-17. Last modified 2026-06-17.