Use-after-free in Vim - CVE-2022-1154

 

Use-after-free in Vim - CVE-2022-1154

Published: March 31, 2022


Vulnerability identifier: #VU61763
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1154
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error within the utf_ptr2char() function in regexp_bt.c. A remote attacker can trick the victim to open a specially crafted file, trigger a use-after-free error and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Vim
IBM Qradar SIEM
Arch Linux
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Oracle Linux
Red Hat Enterprise Linux for x86_64
Ubuntu
Slackware Linux
openEuler
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
Cryostat
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM Robotic Process Automation
Oracle Communications Cloud Native Core Network Exposure Function
Red Hat Advanced Cluster Management for Kubernetes
Red Hat OpenStack
Tanzu Greenplum for Kubernetes
Migration Toolkit for Containers
OpenShift Service Mesh
VMware Tanzu Operations Manager
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
vim (Ubuntu package)
vim-filesystem
vim-minimal
vim-enhanced
vim-common
vim-X11
vim
vim-debuginfo
vim-debugsource
vim (Red Hat package)
app-editors/vim-core
app-editors/vim
app-editors/gvim

How to mitigate CVE-2022-1154

Install updates from vendor's website.

Tanzu Greenplum for Kubernetes - update to 2.0.0
Migration Toolkit for Containers - addressed in versions 1.6.5, 1.7.1, 1.7.2
Cryostat - update to 2.1.0
OpenShift Service Mesh - update to 2.1.3
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.68.2, 3.69.2, 3.70
OpenShift Logging - addressed in versions 5.2.10, 5.3.7, 5.4.1
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 7, 7.5.0 Update Pack 3
IBM Robotic Process Automation - update to 21.0.2.5
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.10, 2.4.4
VMware Tanzu Operations Manager - addressed in versions 2.9.39, 2.10.40
vim (Ubuntu package) - addressed in versions 2:7.4.16893ubuntu1.5+esm4, 2:8.0.1453-1ubuntu1.9, 2:8.1.2269-1ubuntu5.8, 2:8.1.2269-1ubuntu5.9, 2:8.2.3995-1ubuntu2.1
vim-filesystem - update to 8.0.1763-16.0.1
vim-minimal - update to 8.0.1763-16.0.1
vim-enhanced - update to 8.0.1763-16.0.1
vim-common - update to 8.0.1763-16.0.1
vim-X11 - update to 8.0.1763-16.0.1
vim - update to 8.2-26
vim-X11 - update to 8.2-26
vim-common - update to 8.2-26
vim-debuginfo - update to 8.2-26
vim-debugsource - update to 8.2-26
vim-enhanced - update to 8.2-26
vim-minimal - update to 8.2-26
vim-filesystem - update to 8.2-26
vim (Red Hat package) - update to 8.2.2637-16.el9_0.2
vim - addressed in versions 8.2.4701-1.fc34, 8.2.4701-1.fc35, 8.2.4701-1.fc36
app-editors/vim-core - addressed in versions 9.0.0060, 9.0.1157
app-editors/vim - addressed in versions 9.0.0060, 9.0.1157
app-editors/gvim - addressed in versions 9.0.0060, 9.0.1157
vim - update to 9.0.1160-1.1
Red Hat OpenStack - update to 16.2

External References

Related Security Bulletins