Critical Lua Vulnerability in Ubuntu 16.04 Allows Denial of Service and Code Execution

Critical Lua Vulnerability in Ubuntu 16.04 Allows Denial of Service and Code Execution

First seen 8 May 2026, 15:39 UTC UbuntuLinuxsecurity 90% similarity 72.0

Article Content

Browse articles
ThreatCluster

A significant vulnerability (CVE-2025-49844) has been identified in the Lua parser used in Ubuntu 16.04. This flaw allows remote attackers to craft malicious Lua scripts that can crash the Lua interpreter or execute arbitrary code under the user's login. The vulnerability stems from improper handling of garbage collection in the Lua parser. Affected systems include Ubuntu 16.04 LTS with lua5.1 and liblua5.1-0 packages. Users are advised to update their systems to the patched versions provided by Ubuntu Pro. The vulnerability was published on October 3, 2025, and has a known proof of concept dating back to April 13, 2019. Immediate action is recommended to mitigate potential risks.

Key Points: • CVE-2025-49844 allows denial of service and arbitrary code execution in Lua. • Affected systems include Ubuntu 16.04 LTS with lua5.1 and liblua5.1-0 packages. • Users should update to the latest package versions to mitigate the vulnerability.

ThreatCluster AI

Timeline

2019-04-13
First public PoC released
A proof of concept for exploiting the Lua vulnerability was made public.
Linuxsecurity
2025-10-03
CVE-2025-49844 published
A vulnerability in Lua's garbage collection was disclosed, affecting Ubuntu 16.04.
Linuxsecurity
2026-05-08
Security advisory issued
Ubuntu released a security notice urging users to update their systems to patch the Lua vulnerability.
Ubuntu

Community

Browse all →

Tracked Entities in This Story