CVE-2022-28805 singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call leading to a heap-based buffer over
Information published.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
