LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in ljstrfmtwfnum in ljstrfmtnum.c.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/25xxx/CVE-2024-25176.json"
}{
"source": [
"DESCRIPTION",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.1"
}
]
}
{
"source": [
"DESCRIPTION",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "luajit2"
},
{
"fixed": "v2.1-20240626"
}
]
}
[
{
"target": {
"file": "src/lj_str_hash.c"
},
"deprecated": false,
"id": "CVE-2024-25176-0d5129ca",
"signature_version": "v1",
"digest": {
"line_hashes": [
"183120814758655083756228037734727777665",
"293376492445276375190385466200943396306",
"92246439525274422825381664880308763407",
"213516472054757428910352251948889504912",
"164798433512399237947175841704352446607",
"35416535527170111158658476950883124254",
"332954217570182899598154214680945554778"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/openresty/luajit2/commit/dc397b66e6c8065185343cbe5dbeb4532f8e0b92"
},
{
"target": {
"file": "src/lj_strfmt_num.c"
},
"deprecated": false,
"id": "CVE-2024-25176-19801fc3",
"signature_version": "v1",
"digest": {
"line_hashes": [
"184377265502471948946011847305557628028",
"126985615680567155763244816895876325150",
"256480103875299304460977140873185636357",
"150376957051957027109142554037398449154"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/openresty/luajit2/commit/343ce0edaf3906a62022936175b2f5410024cbfc"
},
{
"target": {
"file": "src/lj_str_hash.c",
"function": "str_hash_init_sse42"
},
"deprecated": false,
"id": "CVE-2024-25176-21030966",
"signature_version": "v1",
"digest": {
"function_hash": "274061220364012474765608289785423070953",
"length": 146.0
},
"signature_type": "Function",
"source": "https://github.com/openresty/luajit2/commit/dc397b66e6c8065185343cbe5dbeb4532f8e0b92"
},
{
"target": {
"file": "src/lj_strfmt_num.c"
},
"deprecated": false,
"id": "CVE-2024-25176-a4706ff3",
"signature_version": "v1",
"digest": {
"line_hashes": [
"184377265502471948946011847305557628028",
"126985615680567155763244816895876325150",
"256480103875299304460977140873185636357",
"150376957051957027109142554037398449154"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/luajit/luajit/commit/343ce0edaf3906a62022936175b2f5410024cbfc"
},
{
"target": {
"file": "src/lj_strfmt_num.c",
"function": "lj_strfmt_wfnum"
},
"deprecated": false,
"id": "CVE-2024-25176-da55b03f",
"signature_version": "v1",
"digest": {
"function_hash": "38540755679721982889331743041600852543",
"length": 9111.0
},
"signature_type": "Function",
"source": "https://github.com/openresty/luajit2/commit/343ce0edaf3906a62022936175b2f5410024cbfc"
},
{
"target": {
"file": "src/lj_strfmt_num.c",
"function": "lj_strfmt_wfnum"
},
"deprecated": false,
"id": "CVE-2024-25176-e6c324de",
"signature_version": "v1",
"digest": {
"function_hash": "38540755679721982889331743041600852543",
"length": 9111.0
},
"signature_type": "Function",
"source": "https://github.com/luajit/luajit/commit/343ce0edaf3906a62022936175b2f5410024cbfc"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-25176.json"
"2026-08-12T15:15:05Z"