Low severity3.9NVD Advisory· Published Oct 7, 2024· Updated Jun 17, 2026
CVE-2024-47814
CVE-2024-47814
Description
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- osv-coords15 versionspkg:apk/chainguard/vimpkg:apk/chainguard/vim-docpkg:apk/wolfi/vimpkg:apk/wolfi/vim-docpkg:rpm/opensuse/vim&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/vim&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/vim&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP5pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/vim&distro=SUSE%20Linux%20Micro%206.0
< 9.1.0766-r0+ 14 more
- (no CPE)range: < 9.1.0766-r0
- (no CPE)range: < 9.1.0766-r0
- (no CPE)range: < 9.1.0766-r0
- (no CPE)range: < 9.1.0766-r0
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-150500.20.15.1
- (no CPE)range: < 9.1.0836-17.38.1
- (no CPE)range: < 9.1.0836-17.38.1
- (no CPE)range: < 9.1.1101-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.