Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vims tag file resolution logic when processing the helpfile option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled helpfile option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Neovim | Neovim | * | 0.11.6 (including) |
| Vim | Vim | * | 9.1.2132 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | vim-2:9.1.083-6.el10_1.1 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | vim-2:9.1.083-5.el10_0.2 | * |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | RedHat | vim-2:7.4.629-8.el7_9.1 | * |
| Red Hat Enterprise Linux 8 | RedHat | vim-2:8.0.1763-22.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | vim-2:8.0.1763-22.el8_10 | * |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | vim-2:8.0.1763-13.el8_2.1 | * |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | vim-2:8.0.1763-15.el8_4.1 | * |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | RedHat | vim-2:8.0.1763-15.el8_4.1 | * |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | RedHat | vim-2:8.0.1763-19.el8_6.5 | * |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | RedHat | vim-2:8.0.1763-19.el8_6.5 | * |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | RedHat | vim-2:8.0.1763-19.el8_6.5 | * |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | RedHat | vim-2:8.0.1763-20.el8_8.1 | * |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | RedHat | vim-2:8.0.1763-20.el8_8.1 | * |
| Red Hat Enterprise Linux 9 | RedHat | vim-2:8.2.2637-23.el9_7.1 | * |
| Red Hat Enterprise Linux 9 | RedHat | vim-2:8.2.2637-23.el9_7.1 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | vim-2:8.2.2637-16.el9_0.4 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | vim-2:8.2.2637-20.el9_2.1 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | vim-2:8.2.2637-20.el9_4.2 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | vim-2:8.2.2637-22.el9_6.2 | * |
| Red Hat OpenShift Container Platform 4.12 | RedHat | rhcos-412.86.202604281506-0 | * |
| Red Hat OpenShift Container Platform 4.13 | RedHat | rhcos-413.92.202604080111-0 | * |
| Red Hat OpenShift Container Platform 4.14 | RedHat | rhcos-414.92.202605060243-0 | * |
| Red Hat OpenShift Container Platform 4.15 | RedHat | rhcos-415.92.202605060220-0 | * |
| Red Hat OpenShift Container Platform 4.16 | RedHat | rhcos-416.94.202604211449-0 | * |
| Red Hat OpenShift Container Platform 4.17 | RedHat | rhcos-417.94.202605112123-0 | * |
| Red Hat OpenShift Container Platform 4.18 | RedHat | rhcos-418.94.202604140044-0 | * |
| Red Hat OpenShift Container Platform 4.19 | RedHat | rhcos-4.19.9.6.202604080618-0 | * |
| Red Hat AI Inference Server 3.2 | RedHat | rhaiis/model-opt-cuda-rhel9:1780681984 | * |
| Red Hat AI Inference Server 3.2 | RedHat | rhaiis/vllm-cuda-rhel9:1775740563 | * |
| Red Hat AI Inference Server 3.3 | RedHat | rhaiis/model-opt-cuda-rhel9:1778244559 | * |
| Red Hat AI Inference Server 3.3 | RedHat | rhaiis/vllm-rocm-rhel9:1778244531 | * |
| Red Hat AI Inference Server 3.3 | RedHat | rhaiis/vllm-spyre-rhel9:1778244546 | * |
| Red Hat Insights proxy 1.5 | RedHat | insights-proxy/insights-proxy-container-rhel9:1776868961 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/cds-rhel9:1776868774 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/haproxy-rhel9:1776868744 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/installer-rhel9:1776868772 | * |
| Red Hat Update Infrastructure 5 | RedHat | rhui5/rhua-rhel9:1776868842 | * |
| Vim | Ubuntu | esm-infra-legacy/trusty | * |
| Vim | Ubuntu | esm-infra-legacy/xenial | * |
| Vim | Ubuntu | esm-infra/bionic | * |
| Vim | Ubuntu | esm-infra/focal | * |
| Vim | Ubuntu | esm-infra/xenial | * |
| Vim | Ubuntu | jammy | * |
| Vim | Ubuntu | noble | * |
| Vim | Ubuntu | questing | * |
| Vim | Ubuntu | upstream | * |