Google: app-editors/vim, app-editors/vim-core: security update to 17800.519.47

medium Tenable Cloud Security Plugin ID 454621

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- When switching to other buffers using the :all command and visual mode still being active, this may cause
a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access
beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before
opening other windows and buffers and therefore fix this bug. In addition it does verify that it won't try
to access a position if the position is greater than the corresponding buffer line. Impact is medium since
the user must have switched on visual mode when executing the :all ex command. The Vim project would like
to thank github user gandalf4a for reporting this issue. The issue has been fixed as of Vim patch
v9.1.1003 (CVE-2025-22134)

Solution

Update the app-editors/vim library and its related packages to version 17800.519.47 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-109.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 454621

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.93

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2025-22134

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 1/13/2025

Reference Information

CVE: CVE-2025-22134