The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | Oct 1, 2024 | Aug 15, 2024 |
| Amazon_linux_2023 | — | Upgrade xxd-debuginfoUpgrade vim-debuginfoUpgrade vim-enhancedUpgrade xxdUpgrade vim-enhanced-debuginfoUpgrade vim-filesystemUpgrade vim-dataUpgrade vim-default-editorUpgrade vim-minimal-debuginfoUpgrade vim-commonUpgrade vim-minimalUpgrade vim-debugsource | Feb 17, 2025 | Aug 16, 2024 |
| Debian | — | Upgrade vimNo solution exists | May 15, 2025 | Aug 16, 2024 |
| Huawei Euleros 2_0_sp10 | — | Upgrade vim-enhancedUpgrade vim-filesystemUpgrade vim-commonUpgrade vim-minimal | Nov 11, 2024 | Aug 16, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade vim-filesystemUpgrade vim-commonUpgrade vim-minimalUpgrade vim-enhanced | Dec 12, 2024 | Aug 16, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade vim-minimalUpgrade vim-enhancedUpgrade vim-commonUpgrade vim-filesystem | Nov 26, 2024 | Aug 16, 2024 |
| Huawei Euleros 2_0_sp9 | — | Upgrade vim-filesystemUpgrade vim-enhancedUpgrade vim-commonUpgrade vim-minimal | Nov 11, 2024 | Aug 16, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 16, 2024 |
| Suse | — | Upgrade vimUpgrade vim-dataUpgrade vim-smallUpgrade gvimUpgrade xxdUpgrade vim-data-common | Dec 5, 2025 | Dec 16, 2024 |
| Ubuntu | — | Upgrade vimUpgrade vim (Ubuntu Pro) | Sep 6, 2024 | Aug 16, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 15, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub