CyberRota Analysis
AI-GeneratedThe Lua 5.3 bytecode function parser in radare2 versions prior to 6.2.0 is vulnerable due to improper buffer length checks, allowing it to read beyond the allocated input buffer when processing crafted Lua files. This can lead to invalid parser results or process termination, although no memory disclosure has been observed. Users of radare2, especially those handling Lua bytecode, should prioritize upgrading to version 6.2.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields immediately after a function-name string without checking the remaining buffer length. The vulnerability is triggered by opening or inspecting a crafted Lua 5.3 bytecode file whose function-name string ends at the input-buffer boundary. The parser read two integers and three one-byte fields beyond the allocated input buffer. This can cause invalid parser results or process termination; no attacker-observable memory disclosure has been demonstrated. This issue is fixed in version 6.2.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)