Описание
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
A flaw was found in Vim. When processing an invalid JSON string that spans multiple buffers, the json_decode_item() function can retain a stale pointer. This can lead to the program attempting to read freed memory, potentially resulting in a denial of service for a local user.
Отчет
Red Hat's shipped vim versions across all supported RHEL releases (6 through 10), RHIVOS, and RHCOS are outside the vulnerable range introduced in upstream vim 9.2.0511 and fixed in 9.2.0844 -- RHEL/RHIVOS ship the 7.x, 8.x, or 9.1.x branch depending on release, all of which predate the introduction of this flaw. Fedora and Hummingbird already ship 9.2.920, which is past the fix. No Red Hat product is affected by this vulnerability.
Меры по смягчению последствий
Not applicable -- no Red Hat product ships a vim version within the vulnerable range.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | vim | Not affected | ||
| Red Hat Enterprise Linux 6 | vim | Not affected | ||
| Red Hat Enterprise Linux 7 | vim | Not affected | ||
| Red Hat Enterprise Linux 8 | vim | Not affected | ||
| Red Hat Enterprise Linux 9 | vim | Not affected | ||
| Red Hat Hardened Images | vim | Not affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
Vim is an open source, command line text editor. From 9.2.0511 until 9 ...
EPSS
3.3 Low
CVSS3