CVE-2022-28805
Lua vulnerability analysis and mitigation

Overview

CVE-2022-28805 affects Lua versions from 5.4.0 up to (excluding) 5.4.4. The vulnerability exists in the singlevar function within lparser.c, which lacks a certain luaK_exp2anyregup call. This vulnerability was discovered in early 2022 and affects systems that compile untrusted Lua code (NVD).

Technical details

The vulnerability is a heap-based buffer over-read issue in the Lua programming language. The CVSS v3.1 base score is 9.1 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H. The issue specifically occurs in the singlevar function within lparser.c due to a missing luaK_exp2anyregup call (NVD, Debian).

Impact

The vulnerability can lead to a heap-based buffer over-read condition when compiling untrusted Lua code. This could potentially result in information disclosure and system availability impacts, as indicated by the high confidentiality and availability ratings in the CVSS score (NVD).

Mitigation and workarounds

The vulnerability has been fixed in Lua version 5.4.4. Users should upgrade to this version or later. The fix involves adding the missing luaK_exp2anyregup call in the singlevar function. Various Linux distributions have released security updates to address this vulnerability (Fedora Update, Gentoo).

Additional resources


SourceThis report was generated using AI

Related Lua vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-49844CRITICAL9.9
  • Lua logoLua
  • redis-8.0
NoYesOct 03, 2025
CVE-2022-28805CRITICAL9.1
  • Lua logoLua
  • ntopng
NoYesApr 08, 2022
CVE-2026-24827HIGH7.5
  • Lua logoLua
  • lua
NoYesJan 27, 2026
CVE-2023-4540HIGH7.5
  • Lua logoLua
  • lua5.1-http
NoYesSep 05, 2023
CVE-2022-33099HIGH7.5
  • Lua logoLua
  • lua-static
NoYesJul 01, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management