CVE-2024-47814
published 2024-10-07CVE-2024-47814: Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto…
PriorityP419medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.29%
21.1th percentile
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.0.1378-2+deb12u1 (bookworm) | vim 2:9.0.1378-2+deb12u1 (bookworm) |
| msrc | azl3_vim_9.0.2190-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_vim_9.1.0791-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_vim_9.0.2121-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_vim_9.1.0791-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| vim | vim | < v9.1.0764 | v9.1.0764 |
| vim | vim | < 9.1.0764 | 9.1.0764 |
| vim | vim | >= 0 < 2:8.2.2434-3+deb11u2 | 2:8.2.2434-3+deb11u2 |
| vim | vim | >= 0 < 2:9.0.1378-2+deb12u1 | 2:9.0.1378-2+deb12u1 |
| vim | vim | >= 0 < 2:9.1.0777-1 | 2:9.1.0777-1 |
| vim | vim | >= 0 < 2:9.1.0777-1 | 2:9.1.0777-1 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv4.7MEDIUM
vendor_debian3.9LOW
vendor_msrc3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerability
vendor_ubuntu·2024-11-27
CVE-2024-47814 Vim vulnerability
Title: Vim vulnerability
Summary: Vim could be made to crash if it received specially crafted input.
It was discovered that Vim incorrectly handled memory when closing a
buffer, leading to use-after-free. If a user was tricked into opening a
specially crafted file, an attacker could crash the application, leading to
a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
use-after-free when closing buffers in Vim
vendor_msrc·2024-10-08·CVSS 3.9
CVE-2024-47814 [LOW] CWE-416 use-after-free when closing buffers in Vim
use-after-free when closing buffers in Vim
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.micros
Red Hat
vim: use-after-free when closing buffers in Vim
vendor_redhat·2024-10-07·CVSS 3.9
CVE-2024-47814 [LOW] CWE-416 vim: use-after-free when closing buffers in Vim
vim: use-after-free when closing buffers in Vim
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
A flaw was found in Vim. When closing a buffer visible in a window, a `BufWinLeave` auto command can trigger a use-after-free if this auto command happens to reopen the same b
Debian
CVE-2024-47814: vim - Vim is an open source, command line text editor. A use-after-free was found in V...
vendor_debian·2024·CVSS 3.9
CVE-2024-47814 [LOW] CVE-2024-47814: vim - Vim is an open source, command line text editor. A use-after-free was found in V...
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-2+deb12u1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.1.0777-1)
sid: resolved (fixed in 2:9.1.0777-1)
trixie: resolved (fixed in 2:9.1
OSV
CVE-2024-47814: Vim is an open source, command line text editor
osv·2024-10-07·CVSS 4.7
CVE-2024-47814 [MEDIUM] CVE-2024-47814: Vim is an open source, command line text editor
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
No detection rules found.
No public exploits indexed.
2024-10-07
Published