CVE-2022-3591
published 2022-12-02CVE-2022-3591: Use After Free in GitHub repository vim/vim prior to 9.0.0789.
PriorityP432high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.37%
29.2th percentile
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.0.0813-1 (bookworm) | vim 2:9.0.0813-1 (bookworm) |
| vim | vim | < 9.0.0789 | 9.0.0789 |
| vim | vim | >= 0 < 2:9.0.0813-1 | 2:9.0.0813-1 |
| vim | vim | >= 0 < 2:9.0.0813-1 | 2:9.0.0813-1 |
| vim | vim | >= 0 < 2:9.0.0813-1 | 2:9.0.0813-1 |
| vim | vim | >= 0 < 2:8.1.2269-1ubuntu5.18 | 2:8.1.2269-1ubuntu5.18 |
| vim | vim | >= 0 < 2:8.2.3995-1ubuntu2.12 | 2:8.2.3995-1ubuntu2.12 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm13 | 2:7.4.052-1ubuntu3.1+esm13 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.5+esm14 | 2:7.4.1689-3ubuntu1.5+esm14 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.13+esm5 | 2:8.0.1453-1ubuntu1.13+esm5 |
| vim | vim_vim | >= unspecified < 9.0.0789 | 9.0.0789 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
vim vulnerabilities
osv·2023-10-09·CVSS 7.8
CVE-2022-3235 [HIGH] vim vulnerabilities
vim vulnerabilities
It was discovered that Vim incorrectly handled memory when opening certain
files. If an attacker could trick a user into opening a specially crafted
file, it could cause Vim to crash, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-3235, CVE-2022-3278,
CVE-2022-3297, CVE-2022-3491)
It was discovered that Vim incorrectly handled memory when opening certain
files. If an attacker could trick a user into opening a specially crafted
file, it could cause Vim to crash, or possibly execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04
LTS. (CVE-2022-3352, CVE-2022-4292)
It was discovered that Vim incorrectly handled memory when replacing in
virtualedit mode. An attacker could possibly us
OSV
vim vulnerabilities
osv·2022-12-12·CVSS 7.8
CVE-2022-2345 [HIGH] vim vulnerabilities
vim vulnerabilities
It was discovered that Vim uses freed memory in recurisve substitution of
specially crafted patterns. An attacker could possbly use this to crash Vim
and cause denial of service. (CVE-2022-2345)
It was discovered that Vim makes illegal memory calls when patterns start
with an illegal byte. An attacker could possibly use this to crash Vim,
access or modify memory, or execute arbitrary commands. (CVE-2022-2581)
It was discovered that Vim could be made to crash when parsing invalid line
numbers. An attacker could possbly use this to crash Vim and cause denial
of service. (CVE-2022-3099)
It was discovered that Vim uses freed memory when autocmd changes a mark.
An attacker could possbly use this to crash Vim and cause denial of
service. (CVE-2022-3256)
It was discovered
GHSA
GHSA-c83f-4r5r-pqcw: Use After Free in GitHub repository vim/vim prior to 9
ghsa_unreviewed·2022-12-02
CVE-2022-3591 [HIGH] CWE-416 GHSA-c83f-4r5r-pqcw: Use After Free in GitHub repository vim/vim prior to 9
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
OSV
CVE-2022-3591: Use After Free in GitHub repository vim/vim prior to 9
osv·2022-12-02·CVSS 7.8
CVE-2022-3591 [HIGH] CVE-2022-3591: Use After Free in GitHub repository vim/vim prior to 9
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Red Hat
kernel: hugetlbfs: fix null-ptr-deref in hugetlbfs_parse_param()
vendor_redhat·2025-09-15·CVSS 5.5
CVE-2022-50334 [MEDIUM] CWE-476 kernel: hugetlbfs: fix null-ptr-deref in hugetlbfs_parse_param()
kernel: hugetlbfs: fix null-ptr-deref in hugetlbfs_parse_param()
In the Linux kernel, the following vulnerability has been resolved:
hugetlbfs: fix null-ptr-deref in hugetlbfs_parse_param()
Syzkaller reports a null-ptr-deref bug as follows:
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
RIP: 0010:hugetlbfs_parse_param+0x1dd/0x8e0 fs/hugetlbfs/inode.c:1380
[...]
Call Trace:
vfs_parse_fs_param fs/fs_context.c:148 [inline]
vfs_parse_fs_param+0x1f9/0x3c0 fs/fs_context.c:129
vfs_parse_fs_string+0xdb/0x170 fs/fs_context.c:191
generic_parse_monolithic+0x16f/0x1f0 fs/fs_context.c:231
do_new_mount fs/namespace.c:3036 [inline]
path_mount+0x12de/0x1e20 fs/namespace.c:3370
do_mount fs/namespace.c:3383 [inline]
__do_sys_mount fs/namespace.c:3591 [inline]
__se_sys_mount fs/name
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2023-10-09·CVSS 7.8
CVE-2022-3591 [HIGH] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim incorrectly handled memory when opening certain
files. If an attacker could trick a user into opening a specially crafted
file, it could cause Vim to crash, or possibly execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-3235, CVE-2022-3278,
CVE-2022-3297, CVE-2022-3491)
It was discovered that Vim incorrectly handled memory when opening certain
files. If an attacker could trick a user into opening a specially crafted
file, it could cause Vim to crash, or possibly execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04
LTS. (CVE-2022-3352, CVE-2022-4292)
It was discovered that Vim incorrectly handled memory when
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2022-12-12·CVSS 7.8
CVE-2022-3591 [HIGH] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
It was discovered that Vim uses freed memory in recurisve substitution of
specially crafted patterns. An attacker could possbly use this to crash Vim
and cause denial of service. (CVE-2022-2345)
It was discovered that Vim makes illegal memory calls when patterns start
with an illegal byte. An attacker could possibly use this to crash Vim,
access or modify memory, or execute arbitrary commands. (CVE-2022-2581)
It was discovered that Vim could be made to crash when parsing invalid line
numbers. An attacker could possbly use this to crash Vim and cause denial
of service. (CVE-2022-3099)
It was discovered that Vim uses freed memory when autocmd changes a mark.
An attacker could possbly use this to crash Vim and
Red Hat
vim: Use After Free
vendor_redhat·2022-12-02·CVSS 7.8
CVE-2022-3591 [HIGH] CWE-416 vim: Use After Free
vim: Use After Free
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Statement: Red Hat Product Security has rated this issue as having a Low security impact, because the "victim" has to run an untrusted file IN SCRIPT MODE. Someone who is running untrusted files in script mode is equivalent to someone just taking a random python script and running it.
For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle & Updates Policy: https://access.redhat.com/support/policy/updates/errata/.
Mitigation: Untrusted vim scripts with -s [scriptin] are not recommended to run.
Package: vim (Red Hat Enterprise Linux 6) - Out of support scope
Package: vim (Red Hat Enterprise
Debian
CVE-2022-3591: vim - Use After Free in GitHub repository vim/vim prior to 9.0.0789.
vendor_debian·2022·CVSS 7.8
CVE-2022-3591 [HIGH] CVE-2022-3591: vim - Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Scope: local
bookworm: resolved (fixed in 2:9.0.0813-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0813-1)
sid: resolved (fixed in 2:9.0.0813-1)
trixie: resolved (fixed in 2:9.0.0813-1)
No detection rules found.
No public exploits indexed.
https://github.com/vim/vim/commit/8f3c3c6cd044e3b5bf08dbfa3b3f04bb3f711badhttps://huntr.dev/bounties/a5a998c2-4b07-47a7-91be-dbc1886b3921https://security.gentoo.org/glsa/202305-16https://github.com/vim/vim/commit/8f3c3c6cd044e3b5bf08dbfa3b3f04bb3f711badhttps://huntr.dev/bounties/a5a998c2-4b07-47a7-91be-dbc1886b3921https://security.gentoo.org/glsa/202305-16
2022-12-02
Published