字号 ·· | 护眼
罗塞塔简报

Luarocks.org 被发现存在严重远程代码执行漏洞Luarocks.org 被发现存在严重远程代码执行漏洞

点「原文对照」整页切到原文,或双击某段只看那段的原文。

安全研究员 Vhyrro 在主要的 Lua 包仓库 luarocks.org 中发现了一个严重的远程代码执行 (RCE) 漏洞。

Critical Remote Code Execution Vulnerability Discovered in Luarocks.org Security researcher Vhyrro discovered a critical remote code execution (RCE) vulnerability in luarocks.org, a major Lua package repository. The exploit allowed any user with a regular account to achieve root access on the server by uploading maliciously crafted Lua bytecode. By abusing the KNUM instruction in LuaJIT to read out-of-bounds memory, the researcher was able to pivot to the global environment and execute arbitrary system commands. The vulnerability could have enabled a massive supply chain attack by infecting widely used Lua packages. The issue was patched on September 26, 2026.

该漏洞允许任何拥有普通账户的用户通过上传恶意构造的 Lua 字节码获取服务器的 root 权限。

Critical Remote Code Execution Vulnerability Discovered in Luarocks.org Security researcher Vhyrro discovered a critical remote code execution (RCE) vulnerability in luarocks.org, a major Lua package repository. The exploit allowed any user with a regular account to achieve root access on the server by uploading maliciously crafted Lua bytecode. By abusing the KNUM instruction in LuaJIT to read out-of-bounds memory, the researcher was able to pivot to the global environment and execute arbitrary system commands. The vulnerability could have enabled a massive supply chain attack by infecting widely used Lua packages. The issue was patched on September 26, 2026.

通过滥用 LuaJIT 中的 KNUM 指令读取越界内存,研究人员能够转向全局环境并执行任意系统命令。

Critical Remote Code Execution Vulnerability Discovered in Luarocks.org Security researcher Vhyrro discovered a critical remote code execution (RCE) vulnerability in luarocks.org, a major Lua package repository. The exploit allowed any user with a regular account to achieve root access on the server by uploading maliciously crafted Lua bytecode. By abusing the KNUM instruction in LuaJIT to read out-of-bounds memory, the researcher was able to pivot to the global environment and execute arbitrary system commands. The vulnerability could have enabled a massive supply chain attack by infecting widely used Lua packages. The issue was patched on September 26, 2026.

该漏洞可能通过感染广泛使用的 Lua 包实现大规模供应链攻击。该问题已于 2026 年 9 月 26 日修复。

Critical Remote Code Execution Vulnerability Discovered in Luarocks.org Security researcher Vhyrro discovered a critical remote code execution (RCE) vulnerability in luarocks.org, a major Lua package repository. The exploit allowed any user with a regular account to achieve root access on the server by uploading maliciously crafted Lua bytecode. By abusing the KNUM instruction in LuaJIT to read out-of-bounds memory, the researcher was able to pivot to the global environment and execute arbitrary system commands. The vulnerability could have enabled a massive supply chain attack by infecting widely used Lua packages. The issue was patched on September 26, 2026.