First published: Mon Jan 13 2025(Updated: )
Last updated 21 January 2025
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/vim | <=2:8.2.2434-3+deb11u1<=2:9.0.1378-2<=2:9.1.0967-2 | |
Vim | <9.1.1003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22134 has a high severity due to the potential heap-buffer overflow that can lead to security exploits.
To fix CVE-2025-22134, update Vim to a version that is higher than 9.1.1003.
Affected versions for CVE-2025-22134 include Vim versions up to 9.1.1003.
Yes, if you use Vim on Debian, versions up to 2:9.1.0967-2 are vulnerable to CVE-2025-22134.
CVE-2025-22134 is caused by Vim not properly ending visual mode when switching buffers, leading to a heap-buffer overflow.