lua-users home
lua-l archive

[Date Prev][Date Next][Thread Prev][Thread Next] [Date Index] [Thread Index]


Unrelated as such, but can’t wait for more info about the fuzzer.

Sent from my iPhone

> On Jul 25, 2020, at 21:44, Andrew Gierth <andrew@tao11.riddles.org.uk> wrote:
> 
> 
>> 
>>>>>> "Roberto" == Roberto Ierusalimschy <roberto@inf.puc-rio.br> writes:
> 
>>> We found a heap use after free in lua_checkstack. Here’s the POC:
>>> Lua version 5.4.0, git hash 34affe7a63fc5d842580a9f23616d057e17dfe27
> 
> Roberto> I could not reproduce this one. (But I will look at it again later.)
> 
> I reproduced it using the non-minimized case; it fails in checkstack
> accessing a lua thread that is already freed. So I think this is the
> same problem with graylists as the luaD_call case.
> 
> -- 
> Andrew.