CVE-2025-24014
published 2025-01-20CVE-2025-24014: Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a…
PriorityP424medium5.5CVSS 3.1
AVLACHPRLUIRSUCLILAH
EPSS
0.26%
17.6th percentile
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.1.1113-1 (forky) | vim 2:9.1.1113-1 (forky) |
| vim | vim | < 9.1.1043 | 9.1.1043 |
| vim | vim | >= 0 < 2:9.1.1113-1 | 2:9.1.1113-1 |
| vim | vim | >= 0 < 2:9.1.1113-1 | 2:9.1.1113-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H
osv5.5MEDIUM
vendor_debian4.2LOW
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2025-10-09
CVE-2025-24014 Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Vim could be made to crash if it received specially crafted input.
It was discovered that Vim incorrectly handled certain internal calls when
scrolling a window. An attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Vim vulnerability
vendor_ubuntu·2025-04-01
CVE-2025-24014 Vim vulnerability
Title: Vim vulnerability
Summary: Vim could be made to crash.
USN-7261-1 fixed vulnerabilities in Vim. This update provides
the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
It was discovered that Vim incorrectly handled certain internal calls
when scrolling a window. An attacker could possibly use this issue to
cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Vim vulnerability
vendor_ubuntu·2025-02-10
CVE-2025-24014 Vim vulnerability
Title: Vim vulnerability
Summary: Vim could be made crash.
It was discovered that Vim incorrectly handled certain internal calls
when scrolling a window. An attacker could possibly use this issue to
cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
vim: segmentation fault in win_line() in Vim < 9.1.1043
vendor_redhat·2025-01-20·CVSS 4.2
CVE-2025-24014 [MEDIUM] CWE-787 vim: segmentation fault in win_line() in Vim < 9.1.1043
vim: segmentation fault in win_line() in Vim < 9.1.1043
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.
A flaw was found in Vim. In silent Ex mode (-s -e), Vim typically doesn't show a screen and operates silently in batch mode, however, it is possible to tr
Debian
CVE-2025-24014: vim - Vim is an open source, command line text editor. A segmentation fault was found ...
vendor_debian·2025·CVSS 4.2
CVE-2025-24014 [MEDIUM] CVE-2025-24014: vim - Vim is an open source, command line text editor. A segmentation fault was found ...
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2:9.1.1113-1)
sid: resolved (fixed in 2:9.1.1113-1)
trixie: resolved (fixed in 2:9.1.1113-1)
OSV
CVE-2025-24014: Vim is an open source, command line text editor
osv·2025-01-20·CVSS 5.5
CVE-2025-24014 [MEDIUM] CVE-2025-24014: Vim is an open source, command line text editor
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.
No detection rules found.
No public exploits indexed.
https://github.com/vim/vim/commit/9d1bed5eccdbb46a26b8a484f5e9163c40e63919https://github.com/vim/vim/security/advisories/GHSA-j3g9-wg22-v955http://www.openwall.com/lists/oss-security/2025/01/20/4http://www.openwall.com/lists/oss-security/2025/01/21/1https://security.netapp.com/advisory/ntap-20250314-0005/
2025-01-20
Published