CVE-2024-47814

Name
CVE-2024-47814
Description
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/vim/vim/security/advisories/GHSA-rj48-v4mq-j4vg
MISC https://github.com/vim/vim/commit/51b62387be93c65fa56bbabe1c3

Match rules

CPE URI Source package Min version Max version
vim >= 0 < v9.1.0764

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vim edge-main 9.1.0936-r0 Natanael Copa <ncopa@alpinelinux.org> fixed