Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4097-1 vim security update
EUVD EUVD EUVD-2024-42697 Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Ubuntu USN Ubuntu USN USN-7131-1 Vim vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 18 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Netapp
Netapp bootstrap Os
Netapp hci Compute Node
CPEs cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
Vendors & Products Netapp
Netapp bootstrap Os
Netapp hci Compute Node

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00018}

epss

{'score': 0.0002}


Fri, 11 Apr 2025 22:45:00 +0000

Type Values Removed Values Added
References

Tue, 08 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Oct 2024 01:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Mon, 07 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
Description Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Title use-after-free when closing buffers in Vim
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-11T22:03:20.262Z

Reserved: 2024-10-03T14:06:12.637Z

Link: CVE-2024-47814

cve-icon Vulnrichment

Updated: 2025-04-11T22:03:20.262Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-07T22:15:03.657

Modified: 2025-08-18T17:08:13.370

Link: CVE-2024-47814

cve-icon Redhat

Severity : Low

Publid Date: 2024-10-07T21:16:01Z

Links: CVE-2024-47814 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:42:36Z