CVE-2019-20079: Use After Free
Published Dec 30, 2019
·Updated
Last updated 25 August 2025
Other sources
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
— Launchpad
Affected Software
7 affected componentsFixes available
vim Vim>=8.1.2121<8.1.2136
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.10
debian/vim
2:8.2.2434-3+deb11u12:8.2.2434-3+deb11u32:9.0.1378-2+deb12u22:9.1.1230-22:9.2.0524-12:9.2.0782-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:8.2.2434-3+deb11u1Fixed in 2:8.2.2434-3+deb11u3Fixed in 2:9.0.1378-2+deb12u2Fixed in 2:9.1.1230-2Fixed in 2:9.2.0524-1Fixed in 2:9.2.0782-1 - Upgrade
Upgrade
Vimto a version that resolves this vulnerability.Fixed in 8.1.2136
Event History
Dec 30, 2019
CVE Published
via MITRE·12:04 AM
Data Sourced
via MITRE·12:04 AM
Description
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:25 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:08 PM
RemedyDescriptionSeverityAffected Software
Jul 10, 2026
Data Sourced
via Debian·01:55 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-20079?
CVE-2019-20079 is considered a medium severity vulnerability affecting Vim.
2
How do I fix CVE-2019-20079?
To fix CVE-2019-20079, upgrade Vim to versions 2:8.2.2434-3+deb11u1, 2:9.0.1378-2, or 2:9.1.0709-2.
3
Which versions of Vim are affected by CVE-2019-20079?
Vim versions before 8.1.2136 are affected by CVE-2019-20079.
4
What type of vulnerability is CVE-2019-20079?
CVE-2019-20079 is a use-after-free vulnerability in the autocmd feature of Vim.
5
Is there a risk of exploitation for CVE-2019-20079?
Yes, CVE-2019-20079 poses a risk of exploitation through the execution of malicious Vim scripts.