PT-2025-32593 · Vim+2 · Vim+2
Yang Luo
+1
·
Published
2025-08-11
·
Updated
2025-10-14
·
CVE-2025-55157
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Vim versions 9.1.1231 through 9.1.1399
Description:
Vim is a command line text editor. An error during evaluation when processing nested tuples in Vim script can trigger a use-after-free in Vim’s internal tuple reference management. The
tuple unref() function may access already freed memory due to improper lifetime handling, leading to memory corruption. The exploit requires direct user interaction, as the script must be explicitly executed within Vim.Recommendations:
Update to Vim version 9.1.1400 or later.
Exploit
Fix
Use After Free
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Os
Suse
Vim