CVE-2025-9389

Published: August 27, 2025Last modified: September 2, 2025

Description

A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Notes

From Debian: Introduced with: https://github.com/vim/vim/commit/6897f18ee6e5bb78b32c97616e484030fd514750 (v9.1.1459) Fixed by: https://github.com/vim/vim/commit/b922b30cfe4c044c83bac3cc908084ed20a83598 (v9.1.1683) - https://security-tracker.debian.org/tracker/CVE-2025-9389

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSvimVulnerable (9.1.1552-r0)
25 LTSvimVulnerable (9.1.1566-r0)
StreamvimFixed (9.1.1684-r0)

References

ON THIS PAGE