CVE-2022-3037: Use After Free in vim/vim
Last updated 24 July 2024
Other sources
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/vimto a version that resolves this vulnerability.Fixed in 2:9.0.1378-2+deb12u2Fixed in 2:9.1.1230-1 - Upgrade
Upgrade
vim/vimto a version that resolves this vulnerability.Fixed in 9.0.0322
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3037?
The severity of CVE-2022-3037 is high.
How does CVE-2022-3037 affect GitHub repository vim/vim?
CVE-2022-3037 is a Use After Free vulnerability that affects GitHub repository vim/vim prior to version 9.0.0322.
What is the affected software for CVE-2022-3037?
The affected software for CVE-2022-3037 includes vim packages on Ubuntu (versions up to 2:8.1.2269-1ubuntu5.17 and 2:8.2.3995-1ubuntu2.11), vim package on Ubuntu Jammy (version up to 9.0.0322), and vim packages on Debian (versions up to 2:8.2.2434-3+deb11u1).
How do I fix CVE-2022-3037 on Ubuntu?
To fix CVE-2022-3037 on Ubuntu, update the vim package to version 2:8.1.2269-1ubuntu5.17 or 2:8.2.3995-1ubuntu2.11, or upgrade to a newer Ubuntu release that includes a patched version.
Where can I find more information about CVE-2022-3037?
You can find more information about CVE-2022-3037 on the CVE Mitre website, Ubuntu security notices, and NIST National Vulnerability Database.