Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution. https://github.com/vim/vim/commit/7c824682d2028432ee082703ef0ab399867a089b
Created vim tracking bugs for this issue: Affects: fedora-34 [bug 2083927]
Created vim tracking bugs for this issue: Affects: fedora-35 [bug 2083929]
https://huntr.dev/bounties/520ce714-bfd2-4646-9458-f52cd22bb2fb
Hi, can you please elaborate on how is it possible that RHV is considered affected while RHEL is under investigation? RHV just consume RHEL builds so it's not clear to me how this is possible.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:5242 https://access.redhat.com/errata/RHSA-2022:5242
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:5319 https://access.redhat.com/errata/RHSA-2022:5319
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-1621