CVE-2025-9390

Vulnerability

CVE-2025-9390

vim: vim xxd xxd.c main buffer overflow

ecosystem: redhat:6, redhat:7, redhat:8, redhat:9

A vulnerability was found in the xxd component of Vim in the main function of src/xxd/xxd.c. This flaw allows a local attacker to trigger a buffer overflow, which leads to a denial of service.

References
severityM
Moderate

type: vendor

source: secalert@redhat.com

CVSS3.1
4.4MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

AVLocal
ACLow
PRLow
UINone
SNot Changed
CNone
ILow
ALow

source: secalert@redhat.com

 CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

source: secalert@redhat.com

published: 2025-08-24 14:02:09

modified: 2025-08-31 06:22:55

Detection

redhat:6

OR

unfixedFix deferred

 

vim

package type: source

type: version

tag: rhel-6-els:4308e15c-2db2-f412-2d39-f642ed6f52e8

redhat:7

OR

unfixedFix deferred

 

vim

package type: source

type: version

tag: rhel-7-extras-including-unpatched:43106750-13b2-f412-2d39-f6453fc71339

redhat:8

OR

unfixedFix deferred

 

vim

package type: source

type: version

tag: rhel-8-including-unpatched:4352e74a-89b2-f412-2d39-f659a5bb2ad2

redhat:9

OR

unfixedFix deferred

 

vim

package type: source

type: version

tag: rhel-9-including-unpatched:435a920a-57b2-f412-2d39-f65c0742514b

Data Sources

  • RedHat Enterprise Linux CSAF VEX

    redhat-vex

VulsFutureVuls|GitHub