CVE-2022-1154: Use after free in utf_ptr2char in vim/vim
Last updated 24 July 2024
Other sources
Use after free in utfptr2char in GitHub repository vim/vim prior to 8.2.4646.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-1154?
CVE-2022-1154 is a vulnerability in the utf_ptr2char function in the GitHub repository vim/vim. It is a use after free vulnerability that exists in versions prior to 8.2.4646.
How does CVE-2022-1154 affect Vim?
CVE-2022-1154 affects Vim versions prior to 8.2.4646. It allows an attacker to cause a use after free condition in the utf_ptr2char function, potentially leading to arbitrary code execution.
What is the severity of CVE-2022-1154?
CVE-2022-1154 has a severity rating of high.
How can I fix CVE-2022-1154?
To fix CVE-2022-1154, update Vim to version 8.2.4646 or later.
Where can I find more information about CVE-2022-1154?
You can find more information about CVE-2022-1154 in the references provided: https://huntr.dev/bounties/7f0ec6bc-ea0e-45b0-8128-caac72d23425, https://github.com/vim/vim/commit/b55986c52d4cd88a22d0b0b0e8a79547ba13e1d5, https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C2CQXRLBIC4S7JQVEIN5QXKQPYWB5E3J/