PT-2025-32593 · Vim+2 · Vim+2

·

CVE-2025-55157

·

Published

2025-08-11

·

Updated

2025-10-14

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Vim versions 9.1.1231 through 9.1.1399
Description: Vim is a command line text editor. An error during evaluation when processing nested tuples in Vim script can trigger a use-after-free in Vim’s internal tuple reference management. The tuple unref() function may access already freed memory due to improper lifetime handling, leading to memory corruption. The exploit requires direct user interaction, as the script must be explicitly executed within Vim.
Recommendations: Update to Vim version 9.1.1400 or later.

Exploit

Fix

DoS

Use After Free

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12929
CVE-2025-55157
GHSA-3R4F-MM4W-WGG6
SUSE-SU-2025:03240-1
SUSE-SU-2025:03299-1
SUSE-SU-2025:03300-1
SUSE-SU-2025:20696-1
SUSE-SU-2025:20857-1
SUSE-SU-2025_03299-1
SUSE-SU-2025_03300-1

Affected Products

Red Os
Suse
Vim