RHSA-2022:0894MediumCVSS 7.8

Red Hat Security Advisory: vim security update

Published
March 15, 2022
Last Modified
August 6, 2026

🔗 CVE IDs covered (6)

📋 Description

CVE-2022-0261 — vim: Heap-based buffer overflow in block_insert() in src/ops.c CVE-2022-0318 — vim: Heap-based buffer overflow in utf_head_off() in mbyte.c CVE-2022-0359 — vim: Heap-based buffer overflow in init_ccline() in ex_getln.c CVE-2022-0361 — vim: Illegal memory access when copying lines in visual mode leads to heap buffer overflow CVE-2022-0392 — vim: Heap-based buffer overflow in getexmodeline() in ex_getln.c CVE-2022-0413 — vim: Use after free in src/ex_cmds.c

🎯 Affected products68

  • Red Hat Enterprise Linux AppStream (v. 8)
  • Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-2:8.0.1763-16.el8_5.12.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-X11-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-2:8.0.1763-16.el8_5.12.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-2:8.0.1763-16.el8_5.12.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-2:8.0.1763-16.el8_5.12.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-X11-debuginfo-2:8.0.1763-16.el8_5.12.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-common-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-2:8.0.1763-16.el8_5.12.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-2:8.0.1763-16.el8_5.12.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-2:8.0.1763-16.el8_5.12.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-common-debuginfo-2:8.0.1763-16.el8_5.12.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-debuginfo-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • vim-debuginfo-2:8.0.1763-16.el8_5.12.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • vim-debuginfo-2:8.0.1763-16.el8_5.12.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +38 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Untrusted vim scripts with -s [scriptin] are not recommended to run.

🔗 References (9)