CVE-2025-24014: segmentation fault in win_line() in Vim < 9.1.1043

Published Jan 20, 2025
·
Updated

Last updated 2 April 2025

Other sources

segmentation fault in winline() in Vim < 9.1.1043

Microsoft

Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.

MITRE

Affected Software

9 affected componentsFixes available
vim Vim<9.1.1043
debian/vim<=2:8.2.2434-3+deb11u1, <=2:8.2.2434-3+deb11u3, <=2:9.0.1378-2+deb12u2
2:9.1.1230-1
vim Vim<9.1.1043
All of the following
NetApp Hci Compute Node Firmware
NetApp Hci Compute Node
Microsoft azl3 vim 9.1.0791-4<9.1.0791-3
9.1.0791-3
Microsoft cbl2 vim 9.1.0791-4<9.1.0791-3
9.1.0791-3
Microsoft cbl2 vim 9.1.0791-3<9.1.0791-3
9.1.0791-3
Microsoft azl3 vim 9.1.0791-3<9.1.0791-3
9.1.0791-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/vim to a version that resolves this vulnerability.

    Fixed in 2:9.1.1230-1
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 9.1.0791-3
  3. Upgrade

    Upgrade vim to a version that resolves this vulnerability.

    Fixed in 9.1.1043

Event History

Jan 20, 2025
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
RemedyAffected Software
Jan 29, 2025
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Apr 14, 2025
Data Sourced
via Ubuntu·11:25 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-24014?

CVE-2025-24014 has been identified with a medium severity level due to the potential for a segmentation fault.

2

How do I fix CVE-2025-24014?

To fix CVE-2025-24014, update Vim to version 9.1.1043 or later.

3

What versions of Vim are affected by CVE-2025-24014?

CVE-2025-24014 affects all versions of Vim prior to 9.1.1043.

4

What might happen if I don't address CVE-2025-24014?

If left unaddressed, CVE-2025-24014 could lead to application crashes when using Vim in silent mode.

5

Is CVE-2025-24014 a remote code execution vulnerability?

No, CVE-2025-24014 is not a remote code execution vulnerability; it primarily causes a segmentation fault.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203