CVE-2022-2946: Use After Free in vim/vim
Last updated 24 July 2024
Other sources
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:9.0.1378-2+deb12u2Fixed in 2:9.1.1230-1 - Upgrade
Upgrade
vim/vimto a version that resolves this vulnerability.Fixed in 9.0.0246
Event History
Frequently Asked Questions
What is CVE-2022-2946?
CVE-2022-2946 is a vulnerability that allows for use after free in the GitHub repository vim/vim prior to version 9.0.0246.
How severe is CVE-2022-2946?
CVE-2022-2946 has a CVSS severity score of 7.8, indicating a high severity.
Which software versions are affected by CVE-2022-2946?
The vulnerability affects vim/vim versions prior to 9.0.0246 on Ubuntu and Debian.
How can I fix CVE-2022-2946 on Ubuntu?
To fix CVE-2022-2946 on Ubuntu, update the vim package to version 9.0.0246 or later.
Where can I find more information about CVE-2022-2946?
Additional information about CVE-2022-2946 can be found on the CVE website, Ubuntu Security Notices, and NVD.