> I was recently investigating the state of CVE-2019-6706, and it seems > that while this was fixed in 5.3 branch [1], it was not forward-ported > to 5.4. Is that the case or am I missing some other change that makes > this nonissue? The latter. See http://lua-users.org/lists/lua-l/2020-04/msg00126.html