Google: app-editors/vim, app-editors/vim-core: security update to 18244.236.5

medium Tenable Self-Hosted Container Security Plugin ID 451438

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the
current position in the typeahead buffer but does not check whether there is enough space left in the
buffer to handle the next characters. So this may lead to the tb_off position within the typebuf variable
to point outside of the valid buffer size, which can then later lead to a heap-buffer overflow in e.g.
ins_typebuf(). Therefore, when flushing the typeahead buffer, check if there is enough space left before
advancing the off position. If not, fall back to flush current typebuf contents. It's not quite clear yet,
what can lead to this situation. It seems to happen when error messages occur (which will cause Vim to
flush the typeahead buffer) in comnination with several long mappgins and so it may eventually move the
off position out of a valid buffer size. Impact is low since it is not easily reproducible and requires to
have several mappings active and run into some error condition. But when this happens, this will cause a
crash. The issue has been fixed as of Vim patch v9.1.0697. Users are advised to upgrade. There are no
known workarounds for this issue. (CVE-2024-43802)

Solution

Update the app-editors/vim library and its related packages to version 18244.236.5 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-113.oval.xml.tar.gz

Plugin Details

Severity: Medium

ID: 451438

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.22

Vendor

Vendor Severity: LOW

CVSS v2

Risk Factor: Low

Base Score: 3.7

Temporal Score: 2.7

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2024-43802

CVSS v3

Risk Factor: Medium

Base Score: 4.5

Temporal Score: 3.9

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 8/26/2024

Reference Information

CVE: CVE-2024-43802