U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-47814

Change History

New CVE Received from GitHub, Inc. 10/07/2024 6:15:03 PM

Action Type Old Value New Value
Added Description

								
							
							
						
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Added CVSS V3.1

								
							
							
						
GitHub, Inc. AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Added CWE

								
							
							
						
GitHub, Inc. CWE-416
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/vim/vim/commit/51b62387be93c65fa56bbabe1c3 [No types assigned]
Added Reference

								
							
							
						
GitHub, Inc. https://github.com/vim/vim/security/advisories/GHSA-rj48-v4mq-j4vg [No types assigned]