Bugzilla – Bug 1194301
VUL-0: CVE-2021-4187: vim: use-after-free vulnerability
Last modified: 2022-01-04 15:45:55 UTC
rh#2036129 Vim is vulnerable to use-after-free. Reference: https://huntr.dev/bounties/a8bee03a-6e2e-43bf-bee3-4968c5386a2e Upstream patch: https://github.com/vim/vim/commit/4bf1006cae7e87259ccd5219128c3dba75774441 References: https://bugzilla.redhat.com/show_bug.cgi?id=2036129 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-4187 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-4187 https://github.com/vim/vim/commit/4bf1006cae7e87259ccd5219128c3dba75774441 https://huntr.dev/bounties/a8bee03a-6e2e-43bf-bee3-4968c5386a2e
I could not reproduce the crash on any codestreams, SLE nor openSUSE, only on newer upstream versions. Closing.