CVE-2022-2210: Out-of-bounds Write in vim/vim
Last updated 24 July 2024
Other sources
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:9.0.1378-2+deb12u2Fixed in 2:9.1.1230-1 - Upgrade
Upgrade
vim/vimto a version that resolves this vulnerability.Fixed in 8.2
Event History
Frequently Asked Questions
What is CVE-2022-2210?
CVE-2022-2210 is an out-of-bounds write vulnerability in the GitHub repository vim/vim prior to version 8.2.
How does CVE-2022-2210 impact the affected software?
CVE-2022-2210 allows an attacker to write data outside the bounds of allocated memory, which can lead to a crash or arbitrary code execution.
Which versions of Ubuntu are affected by CVE-2022-2210?
Ubuntu versions 14.04 (Trusty), 16.04 (Xenial), 18.04 (Bionic), and 20.04 (Focal) with the vim package are affected by CVE-2022-2210.
How can I fix CVE-2022-2210 on Ubuntu?
To fix CVE-2022-2210 on Ubuntu, update the vim package to versions 2:7.4.052-1ubuntu3.1+ (Trusty), 2:7.4.1689-3ubuntu1.5+ (Xenial), 2:8.0.1453-1ubuntu1.13+ (Bionic), or 2:8.1.2269-1ubuntu5.16 (Focal).
Are the latest upstream versions of vim vulnerable to CVE-2022-2210?
No, the latest upstream version of vim, 8.2.5164, is not vulnerable to CVE-2022-2210.