Critical Lua Vulnerability in Ubuntu 16.04 Allows Denial of Service and Code Execution
Article Content
- •CVE-2025-49844 allows denial of service and arbitrary code execution in Lua.
- •Affected systems include Ubuntu 16.04 LTS with lua5.1 and liblua5.1-0 packages.
- •Users should update to the latest package versions to mitigate the vulnerability.
A significant vulnerability (CVE-2025-49844) has been identified in the Lua parser used in Ubuntu 16.04. This flaw allows remote attackers to craft malicious Lua scripts that can crash the Lua interpreter or execute arbitrary code under the user's login. The vulnerability stems from improper handling of garbage collection in the Lua parser. Affected systems include Ubuntu 16.04 LTS with lua5.1 and liblua5.1-0 packages. Users are advised to update their systems to the patched versions provided by Ubuntu Pro. The vulnerability was published on October 3, 2025, and has a known proof of concept dating back to April 13, 2019. Immediate action is recommended to mitigate potential risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2025-49844 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical PostgreSQL Vulnerability Exposes Databases to Remote Code Execution A critical vulnerability, tracked as CVE-2026-6471 and dubbed PostGREShell, has been discovered in PostgreSQL, affecting versions since 2014. This flaw allows attackers with low-privilege replication accounts to execute arbitrary code on the database server, leading to full database and server compromise. The…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…