# lua51 5.1.5

Snapshot of gominimal/pkgs commit `75fcc0c216a965906cff4df6f7c16cf03acdca5b` (pushed 2026-08-23T17:32:57.000Z).

## Install

```sh
min add lua51
```

## Direct advisories

| ID | Severity | CVSS | Fix status | Fixed version | Summary |
| --- | --- | --- | --- | --- | --- |
| CVE-2014-5461 | UNKNOWN | — | unknown_fix | — | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments. |

## Transitive advisories

2 advisories inherited through runtime dependencies:

- CVE-2026-5435 (HIGH) via glibc
- CVE-2026-6238 (MEDIUM) via glibc

## Dependencies

- Build (3): base, make, toolchain
- Runtime (1): glibc

## Links

- Package page (HTML): https://minimal.dev/pkgs/lua51
- JSON API (floats latest): https://minimal.dev/api/pkgs/lua51.json
- SBOM (CycloneDX 1.5): https://minimal.dev/api/pkgs/lua51/sbom.json
