CVE-2025-26205: Lua lpeg vulnerability
Published Mar 9, 2025
·Updated
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Affected Software
1 affected component
Lua LPeg
Event History
Mar 9, 2025
CVE Published
via MITRE·12:00 AM
Rejected
via MITRE·12:00 AM
Rejected
via MITRE·09:14 PM
Data Sourced
via NVD·09:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2025-26205?
The severity of CVE-2025-26205 is currently disputed but it is associated with an out-of-bounds read and potential segmentation violation.
2
How do I fix CVE-2025-26205?
To mitigate CVE-2025-26205, upgrade to a newer version of Lua that addresses this vulnerability.
3
Which versions of Lua are affected by CVE-2025-26205?
Lua versions prior to 5.4.7 are affected by CVE-2025-26205 due to issues in the debug library.
4
What are the repercussions of CVE-2025-26205?
CVE-2025-26205 could lead to application crashes or undefined behavior when the debug library is utilized.
5
Is CVE-2025-26205 publicly known?
Yes, CVE-2025-26205 is a publicly reported vulnerability within the Lua programming language.