Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9389

Опубликовано: 24 авг. 2025
Источник: redhat
CVSS3: 3.3

Описание

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

Отчет

A memory corruption vulnerability exists in the Vim text editor's __memmove_avx_unaligned_erms() function (memmove-vec-unaligned-erms.S file). This issue can be triggered by a local attacker with low privileges who convinces a user to open a specially crafted file. Exploitation of this flaw leads to an application crash, resulting in a denial of service (DoS) that impacts system Availability.

Меры по смягчению последствий

At the time of this analysis, an official patch has not been released. Users should upgrade to vim-9.1.0000 or the latest version.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimFix deferred
Red Hat Enterprise Linux 6vimNot affected
Red Hat Enterprise Linux 7vimNot affected
Red Hat Enterprise Linux 8vimNot affected
Red Hat Enterprise Linux 9vimNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2390597vim: vim memmove-vec-unaligned-erms.S __memmove_avx_unaligned_erms memory corruption

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
24 дня назад

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

CVSS3: 3.3
nvd
24 дня назад

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

CVSS3: 3.3
debian
24 дня назад

A vulnerability was identified in vim 9.1.0000. Affected is the functi ...

CVSS3: 3.3
github
24 дня назад

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

3.3 Low

CVSS3