VYPR
Unrated severityNVD Advisory· Published Sep 6, 2022· Updated Nov 3, 2025

Use After Free in vim/vim

CVE-2022-3134

Description

Use-after-free in Vim's tag search when 'tagfunc' closes the window, leading to crash or potential code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Use-after-free in Vim's tag search when 'tagfunc' closes the window, leading to crash or potential code execution.

Vulnerability

A use-after-free vulnerability exists in Vim's do_tag function when the 'tagfunc' option is used. If a custom tag function closes the window during tag searching, Vim continues to use a pointer to the tag stack that may have been freed, leading to a crash. This affects Vim versions prior to 9.0.0389 [1].

Exploitation

An attacker must be able to set a malicious 'tagfunc' that closes the current window while Vim is searching for tags. This can be achieved by crafting a file or plugin that triggers the vulnerable code path. No authentication is required if the attacker can convince a user to open a specially crafted file or execute a command that invokes the tag function [1].

Impact

Successful exploitation results in a use-after-free condition, which can cause a denial of service (crash) and potentially allow arbitrary code execution in the context of the Vim process. The vulnerability is rated with a CVSS score of 7.8 (High) [2].

Mitigation

The vulnerability is fixed in Vim version 9.0.0389, released on 2022-09-06 [1]. Users should upgrade to this version or later. Gentoo Linux recommends upgrading to version 9.0.1157 or higher [2]. No workaround is available; upgrading is the only mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

41

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.