| Name | CVE-2026-40959 |
| Description | Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-6217-1 |
| Debian Bugs | 1133919 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| luanti (PTS) | trixie | 5.10.0+dfsg-5 | vulnerable |
| trixie (security) | 5.10.0+dfsg-5+deb13u1 | fixed |
| forky, sid | 5.15.2+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| luanti | source | trixie | 5.10.0+dfsg-5+deb13u1 | | DSA-6217-1 | |
| luanti | source | (unstable) | 5.15.2+dfsg-1 | | | 1133919 |
Notes
https://github.com/luanti-org/luanti/security/advisories/GHSA-g596-mf82-w8c3
https://github.com/luanti-org/luanti/commit/8a929dfb97aa08337f49ba1bb96a56d6557dc896 (master)
https://github.com/luanti-org/luanti/commit/53cef183e2a85a4daff84ac1a9a7946f940da8f8 (5.15.2)