Back

HIGH

Heap-based Buffer Overflow in vim/vim

Published Nov 25, 2022

Description

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file in script mode. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.

Red Hat mitigation

Untrusted vim scripts with -s [scriptin] are not recommended to run.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Nov 25, 2022
Updated Nov 3, 2025
Reserved Nov 25, 2022
CISA Vulnrichment
Updated Apr 14, 2025
NVD
Status Analyzed
Modified Sep 24, 2026
Red Hat
Severity Low
Public date Nov 25, 2022