[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-MGASA-2026-0225":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T11:19:25.255Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":24,"duplicates":25,"related":26,"reserved_at":9,"published_at":27,"modified_at":28,"state":9,"summary":29,"references_raw":31,"kevs":52,"epss":9,"epss_history":53,"metrics":54,"affected":55},"MGASA-2026-0225","Updated luajit packages fix security vulnerabilities\n\nIn LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other\nproducts, debug.getinfo has a type confusion issue that leads to\narbitrary memory write or read operations, because certain cases\ninvolving valid stack levels and > options are mishandled.\n(CVE-2019-19391)\nLuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in\nlj_err.c. (CVE-2020-24372)\nLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a\nstack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.\n(CVE-2024-25176)\nLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an\nunsinking of IR_FSTORE for NULL metatable, which leads to Denial of\nService (DoS). (CVE-2024-25177)\nLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an\nout-of-bounds read in the stack-overflow handler in lj_state.c.\n(CVE-2024-25178)\n",null,[],[],[],[14,16,18,20,22],{"_key":15},"CVE-2019-19391",{"_key":17},"CVE-2020-24372",{"_key":19},"CVE-2024-25176",{"_key":21},"CVE-2024-25177",{"_key":23},"CVE-2024-25178",[],[],[],"2026-06-18T21:28:22Z","2026-06-18T21:30:04.565170803Z",{"cisa_kev":30,"cisa_ransomware":30,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[32,38,43,48],{"url":33,"sources":34,"tags":36},"https://advisories.mageia.org/MGASA-2026-0225.html",[35],"osv_mageia",[37],"Advisory",{"url":39,"sources":40,"tags":41},"https://bugs.mageia.org/show_bug.cgi?id=34491",[35],[42],"REPORT",{"url":44,"sources":45,"tags":46},"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XU3NWLH45W4F7OBKEB4XEOJQI4S36PU5/",[35],[47],"WEB",{"url":49,"sources":50,"tags":51},"https://lists.debian.org/debian-lts-announce/2025/08/msg00022.html",[35],[47],[],[],[],[56],{"ecosystem":57,"name":58,"vendor":59,"product":58,"cpe_part":9,"purl_type":60,"purl_namespace":59,"purl_name":58,"source":9,"versions":61},"Mageia","luajit","mageia","rpm",[62],{"version":63,"is_range":64,"range_type":65,"version_start":9,"version_start_type":9,"version_end":66,"version_end_type":67,"fixed_in":9},"lt2_1_0_0_beta3_10_1_mga9",true,"ecosystem","2.1.0-0.beta3.10.1.mga9","excluding"]