Lua attraverso 5.4.0 permette un redzone croce pila in luaO_pushvfstring perché un meccanismo di protezione chiama erroneamente luaD_callnoyield due volte di seguito.
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QA5Q5MDQMTGXRQO3PAQ4EZFTYWJXZM5N/
http://lua-users.org/lists/lua-l/2020-07/msg00052.html
https://github.com/lua/lua/commit/34affe7a63fc5d842580a9f23616d057e17dfe27
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-24342