CVE-2024-31446

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-31446
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-31446.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-31446
Related
  • GHSA-54j4-xpgj-cq4g
Published
2024-04-16T20:15:10Z
Modified
2025-07-01T15:48:44.789408Z
Summary
[none]
Details

OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. A user can use OpenComputers to get a Computer thread stuck in the Lua VM, which eventually blocks the Server thread, requiring the server to be forcibly shut down. This can be accomplished using any device in the mod and can be performed by anyone who can execute Lua code on them. This occurs while using the native Lua library. LuaJ appears to not have this issue. This vulnerability is fixed in 1.8.4. The GregTech: New Horizons modpack uses its own modified version of OpenComputers. They have applied the relevant patch in version 1.10.10-GTNH.

References

Affected packages

Git / github.com/mightypirates/opencomputers

Affected ranges

Type
GIT
Repo
https://github.com/mightypirates/opencomputers
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.7.10-forge/1.7.6
1.7.10-forge/1.7.7
1.7.10-forge/1.8.0
1.7.10-forge/1.8.0-snapshot-20220917
1.7.10-forge/1.8.0-snapshot-20220918
1.7.10-forge/1.8.1
1.7.10-forge/1.8.2
1.7.10-forge/1.8.3
1.7.10-forge/v1.8.0-snapshot-20220917

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.5a
v1.1.0
v1.1.0pre1
v1.1.0pre2
v1.1.0pre2a
v1.1.0pre3
v1.1.0pre4
v1.1.0pre4a
v1.1.1
v1.1.2
v1.1.2a
v1.1.3
v1.2.0
v1.2.0-pre1
v1.2.0-pre2
v1.2.0-pre2a
v1.2.0-pre3
v1.2.1
v1.2.10
v1.2.11
v1.2.12
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.2.9
v1.3.0
v1.3.0-beta.1
v1.3.0-rc.1
v1.3.1
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.4.0-beta.1
v1.4.6
v1.5.0-beta.1
v1.7.0
v1.7.1
v1.7.2
v1.7.3
v1.7.4
v1.7.5
v1.8.0-snapshot-20220917

v2.*

v2.0.0
v2.0.0-pre1
v2.0.1