CVE-2025-26603
published 2025-02-18CVE-2025-26603: Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables…
PriorityP418medium4.2CVSS 3.1
AVLACHPRLUIRSUCLILAL
EPSS
0.23%
14.1th percentile
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a register, Vim will free the register content before storing the new content in the register. Now when redirecting the `:display` command to a register that is being displayed, Vim will free the content while shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the ex_display() function, that it does not try to redirect to a register while displaying this register at the same time. However this check is not complete, and so Vim does not check the `+` and `*` registers (which typically donate the X11/clipboard registers, and when a clipboard connection is not possible will fall back to use register 0 instead. In Patch 9.1.1115 Vim will therefore skip outputting to register zero when trying to redirect to the clipboard registers `*` or `+`. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.1.1230-1 (forky) | vim 2:9.1.1230-1 (forky) |
| msrc | azl3_vim_9.1.0791-4_on_azure_linux_3.0 | — | — |
| msrc | cbl2_vim_9.1.0791-4_on_cbl_mariner_2.0 | — | — |
| vim | vim | < 9.1.1115 | 9.1.1115 |
| vim | vim | >= 0 < 2:9.1.1230-1 | 2:9.1.1230-1 |
| vim | vim | >= 0 < 2:9.1.1230-1 | 2:9.1.1230-1 |
| vim | vim | >= 0 < 2:8.1.2269-1ubuntu5.32 | 2:8.1.2269-1ubuntu5.32 |
| vim | vim | >= 0 < 2:8.2.3995-1ubuntu2.24 | 2:8.2.3995-1ubuntu2.24 |
| vim | vim | >= 0 < 2:9.1.0016-1ubuntu7.8 | 2:9.1.0016-1ubuntu7.8 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm21 | 2:7.4.052-1ubuntu3.1+esm21 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.5+esm27 | 2:7.4.1689-3ubuntu1.5+esm27 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.13+esm12 | 2:8.0.1453-1ubuntu1.13+esm12 |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
osv4.2MEDIUM
vendor_debian4.2LOW
vendor_msrc4.2MEDIUM
vendor_redhat4.2MEDIUM
vendor_ubuntu2.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2025-04-07·CVSS 2.8
CVE-2025-26603 [LOW] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Vim could be made to crash if it received specially crafted input.
It was discovered that Vim incorrectly handled memory when using invalid
input with the log option. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS and
Ubuntu 24.10. (CVE-2025-1215)
It was discovered that Vim incorrectly handled memory when redirecting
certain output to the register. An attacker could possibly use this issue
to cause a denial of service. (CVE-2025-26603)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
vim: heap-use-after-free in function str_to_reg in vim/vim
vendor_redhat·2025-02-18·CVSS 4.2
CVE-2025-26603 [MEDIUM] CWE-416 vim: heap-use-after-free in function str_to_reg in vim/vim
vim: heap-use-after-free in function str_to_reg in vim/vim
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a register, Vim will free the register content before storing the new content in the register. Now when redirecting the `:display` command to a register that is being displayed, Vim will free the content while shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the ex_display() function, that it does not try to redirect to a register while displaying this register at the same t
Microsoft
heap-use-after-free in function str_to_reg in vim/vim
vendor_msrc·2025-02-11·CVSS 4.2
CVE-2025-26603 [MEDIUM] CWE-416 heap-use-after-free in function str_to_reg in vim/vim
heap-use-after-free in function str_to_reg in vim/vim
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://l
Debian
CVE-2025-26603: vim - Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to ...
vendor_debian·2025·CVSS 4.2
CVE-2025-26603 [MEDIUM] CVE-2025-26603: vim - Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to ...
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a register, Vim will free the register content before storing the new content in the register. Now when redirecting the `:display` command to a register that is being displayed, Vim will free the content while shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the ex_display() function, that it does not try to redirect to a register while displaying this register at the same time. However this check is not complete, and so Vim does not
OSV
vim vulnerabilities
osv·2025-04-07·CVSS 2.4
CVE-2025-1215 [LOW] vim vulnerabilities
vim vulnerabilities
It was discovered that Vim incorrectly handled memory when using invalid
input with the log option. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS and
Ubuntu 24.10. (CVE-2025-1215)
It was discovered that Vim incorrectly handled memory when redirecting
certain output to the register. An attacker could possibly use this issue
to cause a denial of service. (CVE-2025-26603)
OSV
CVE-2025-26603: Vim is a greatly improved version of the good old UNIX editor Vi
osv·2025-02-18·CVSS 4.2
CVE-2025-26603 [MEDIUM] CVE-2025-26603: Vim is a greatly improved version of the good old UNIX editor Vi
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a register, Vim will free the register content before storing the new content in the register. Now when redirecting the `:display` command to a register that is being displayed, Vim will free the content while shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the ex_display() function, that it does not try to redirect to a register while displaying this register at the same time. However this check is not complete, and so Vim does not
No detection rules found.
No public exploits indexed.
2025-02-18
Published