PT-2025-32593 · Vim+2 · Vim+2

Yang Luo

+1

·

Publicado

2025-08-11

·

Atualizado

2025-10-14

·

CVE-2025-55157

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Vim versions 9.1.1231 through 9.1.1399
Description: Vim is a command line text editor. An error during evaluation when processing nested tuples in Vim script can trigger a use-after-free in Vim’s internal tuple reference management. The tuple unref() function may access already freed memory due to improper lifetime handling, leading to memory corruption. The exploit requires direct user interaction, as the script must be explicitly executed within Vim.
Recommendations: Update to Vim version 9.1.1400 or later.

Exploit

Correção

Use After Free

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12929
CVE-2025-55157
GHSA-3R4F-MM4W-WGG6
SUSE-SU-2025:03240-1
SUSE-SU-2025:03299-1
SUSE-SU-2025:03300-1
SUSE-SU-2025:20696-1
SUSE-SU-2025:20857-1
SUSE-SU-2025_03299-1
SUSE-SU-2025_03300-1

Produtos afetados

Red Os
Suse
Vim