The vendor explicitly identifies these products as affected by this CVE.
- vim-X11 as a component of Red Hat Enterprise Linux 10
- vim-common as a component of Red Hat Enterprise Linux 10
- vim-data as a component of Red Hat Enterprise Linux 10
- vim-enhanced as a component of Red Hat Enterprise Linux 10
- vim-filesystem as a component of Red Hat Enterprise Linux 10
- vim-minimal as a component of Red Hat Enterprise Linux 10
- vim.src as a component of Red Hat Enterprise Linux 10
- xxd as a component of Red Hat Enterprise Linux 10
- Summary
- A memory corruption vulnerability was found in the Vim, where the flaw resides in the __memmove_avx_unaligned_erms() function, located in the memmove-vec-unaligned-erms.S file. The vulnerability is caused by improper handling of memory operations within this function, which can be triggered when a user opens a specially crafted file. An attacker on the local system can exploit this flaw to cause the Vim application to crash. This crash leads to a denial of service.
- Remediation
- At the time of this analysis, an official patch has not been released. Users should upgrade to vim-9.1.0000 or the latest version.
