Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
{
"cpes": [
"cpe:2.3:a:lua:lua:5.4.0:-:*:*:*:*:*:*",
"cpe:2.3:a:lua:lua:*:*:*:*:*:*:*:*"
],
"severity": "High"
}