CVE-2022-0156
Published: 10 January 2022
vim is vulnerable to Use After Free
Priority
CVSS 3 base score: 5.5
Status
Package | Release | Status |
---|---|---|
vim Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(code not present)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Needed
|
|
jammy |
Needed
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Released
(8.2.4042)
|
|
xenial |
Not vulnerable
(code not present)
|
Notes
Author | Note |
---|---|
ccdm94 | patches 8.2.4040 and 8.2.4042 are both needed (as defined by upstream). This patch makes changes to the code introduced by the patch for CVE-2021-4173. |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0156
- https://huntr.dev/bounties/47dded34-3767-4725-8c7c-9dcb68c70b36
- https://github.com/vim/vim/commit/9f1a39a5d1cd7989ada2d1cb32f97d84360e050f (v8.2.4040)
- NVD
- Launchpad
- Debian