PT-2025-32593 · Vim+2 · Vim+2

Yang Luo

+1

·

Published

2025-08-11

·

Updated

2025-10-14

·

CVE-2025-55157

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Vim versions 9.1.1231 through 9.1.1399
Description: Vim is a command line text editor. An error during evaluation when processing nested tuples in Vim script can trigger a use-after-free in Vim’s internal tuple reference management. The tuple unref() function may access already freed memory due to improper lifetime handling, leading to memory corruption. The exploit requires direct user interaction, as the script must be explicitly executed within Vim.
Recommendations: Update to Vim version 9.1.1400 or later.

Exploit

Fix

Use After Free

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-12929
CVE-2025-55157
GHSA-3R4F-MM4W-WGG6
SUSE-SU-2025:03240-1
SUSE-SU-2025:03299-1
SUSE-SU-2025:03300-1
SUSE-SU-2025:20696-1
SUSE-SU-2025:20857-1
SUSE-SU-2025_03299-1
SUSE-SU-2025_03300-1

Affected Products

Red Os
Suse
Vim