CVE-2022-2183: Out-of-bounds Read in vim/vim
Last updated 24 July 2024
Other sources
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:9.0.1378-2+deb12u2Fixed in 2:9.1.1230-1 - Upgrade
Upgrade
vim/vimto a version that resolves this vulnerability.Fixed in 8.2
Event History
Frequently Asked Questions
What is CVE-2022-2183?
CVE-2022-2183 is an out-of-bounds read vulnerability in the GitHub repository vim/vim prior to version 8.2.
What software is affected by CVE-2022-2183?
The software affected by CVE-2022-2183 includes versions 2:8.0.1453-1ubuntu1.12, 2:8.1.2269-1ubuntu5.13, 2:8.2.3995-1ubuntu2.5, 8.2.5151, and 2:8.1.0875-5+deb10u2, 2:8.1.0875-5+deb10u5, 2:8.2.2434-3+deb11u1.
How severe is CVE-2022-2183?
CVE-2022-2183 is a vulnerability with an out-of-bounds read, which can potentially lead to information disclosure or a denial of service.
How do I fix CVE-2022-2183?
To fix CVE-2022-2183, update your vim package to version 8.2.5151 or higher if available, or follow the recommended remedies provided by your operating system's security notice.
Where can I find more information about CVE-2022-2183?
You can find more information about CVE-2022-2183 on the MITRE CVE website and the Ubuntu security notices (USN-5723-1, USN-5995-1).