Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-9389

Опубликовано: 24 авг. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

Отчет

A memory corruption vulnerability exists in the Vim text editor's __memmove_avx_unaligned_erms() function (memmove-vec-unaligned-erms.S file). This issue can be triggered by a local attacker with low privileges who convinces a user to open a specially crafted file. Exploitation of this flaw leads to an application crash, resulting in a denial of service (DoS) that impacts system Availability.

Меры по смягчению последствий

At the time of this analysis, an official patch has not been released. Users should upgrade to vim-9.1.0000 or the latest version.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimFix deferred
Red Hat Enterprise Linux 6vimNot affected
Red Hat Enterprise Linux 7vimNot affected
Red Hat Enterprise Linux 8vimNot affected
Red Hat Enterprise Linux 9vimNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2390597vim: vim memmove-vec-unaligned-erms.S __memmove_avx_unaligned_erms memory corruption

EPSS

Процентиль: 6%
0.00027
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
2 месяца назад

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

CVSS3: 3.3
nvd
2 месяца назад

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

CVSS3: 3.3
debian
2 месяца назад

A vulnerability was identified in vim 9.1.0000. Affected is the functi ...

CVSS3: 3.3
github
2 месяца назад

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

CVSS3: 5.5
fstec
2 месяца назад

Уязвимость функции __memmove_avx_unaligned_erms() файла memmove-vec-unaligned-erms.S текстового редактора vim, позволяющая нарушителю выполнить вызвать отказ в обслуживании

EPSS

Процентиль: 6%
0.00027
Низкий

3.3 Low

CVSS3