CVE-2024-47814

NameCVE-2024-47814
DescriptionVim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1084806

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
vim (PTS)jessie, jessie (lts)2:7.4.488-7+deb8u11vulnerable
stretch (security)2:8.0.0197-4+deb9u7vulnerable
stretch (lts), stretch2:8.0.0197-4+deb9u11vulnerable
buster (security), buster, buster (lts)2:8.1.0875-5+deb10u6vulnerable
bullseye2:8.2.2434-3+deb11u1vulnerable
bookworm2:9.0.1378-2vulnerable
sid, trixie2:9.1.0861-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
vimsource(unstable)2:9.1.0777-11084806

Notes

[bookworm] - vim <no-dsa> (Minor issue)
[bullseye] - vim <postponed> (Minor issue)
https://github.com/vim/vim/security/advisories/GHSA-rj48-v4mq-j4vg
https://github.com/vim/vim/commit/51b62387be93c65fa56bbabe1c3 (v9.1.0764)
[buster] - vim <postponed> (Minor issue)
[stretch] - vim <postponed> (Minor issue)
[jessie] - vim <postponed> (Minor issue)

Search for package or bug name: Reporting problems