{"id":"CVE-2025-1215","summary":"vim main.c memory corruption","details":"A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.","modified":"2026-07-30T14:09:01.120095Z","published":"2025-02-12T18:31:06.472Z","related":["SUSE-SU-2025:0722-1","SUSE-SU-2025:0723-1","SUSE-SU-2025:0724-1","SUSE-SU-2025:20128-1"],"database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1215.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1215.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1215"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250321-0005/"},{"type":"ADVISORY","url":"https://vuldb.com/?id.295174"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.497546"},{"type":"REPORT","url":"https://github.com/vim/vim/issues/16606"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.295174"},{"type":"FIX","url":"https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9"},{"type":"FIX","url":"https://github.com/vim/vim/releases/tag/v9.1.1097"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vim/vim","events":[{"introduced":"97baa1cfe83c08eff1a452aca8d91f51112ca932"},{"fixed":"c5654b84480822817bb7b69ebc97c174c91185e9"}],"database_specific":{"extracted_events":[{"introduced":"9.1.1096"},{"last_affected":"9.1.1096"},{"introduced":"0"},{"fixed":"9.1.1097"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*"}}],"versions":["9.1.1096","v9.1.1096"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-1215.json","vanir_signatures_modified":"2026-07-30T14:09:01Z","vanir_signatures":[{"id":"CVE-2025-1215-31d46273","signature_type":"Function","signature_version":"v1","source":"https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9","target":{"file":"src/main.c","function":"common_init"},"deprecated":false,"digest":{"function_hash":"42447114149806573033898505403371006296","length":1289}},{"target":{"file":"src/main.c","function":"endif"},"deprecated":false,"digest":{"length":4564,"function_hash":"284133475238388592398491348037293250304"},"id":"CVE-2025-1215-4a8086f7","signature_type":"Function","signature_version":"v1","source":"https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9"},{"digest":{"line_hashes":["37074130246431066121523056618065352525","209818327268670002301727105315340373056","173513180267139333535873256353314448037","233233797750255586888635555666886017793","145094471957471180977394572199403657491","289276279076538026489247078484211046900","74993261675509711571609258578475857398","309947370752383641005882110864921058003","339991501923586881957155468761141226904","89050162474555063000094646800947443065","197913811015611464365727182439367674096","297416392397801331366762717589231468282","147997946695856715542786412620466817763","293622845078576378956369280950122740128","148572888913468120928719192432854405941","310251206451606994053016115088915688274"],"threshold":0.9},"id":"CVE-2025-1215-81d63039","signature_type":"Line","signature_version":"v1","source":"https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9","target":{"file":"src/main.c"},"deprecated":false},{"id":"CVE-2025-1215-8d9709db","signature_type":"Function","signature_version":"v1","source":"https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9","target":{"file":"src/message_test.c","function":"main"},"deprecated":false,"digest":{"function_hash":"83858829964796490194210856689146029031","length":431}},{"signature_version":"v1","source":"https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9","target":{"file":"src/version.c"},"deprecated":false,"digest":{"line_hashes":["146200493773228420153804765641940418619","255647411661596530030148880846932926380","106686045972672276732200938893951594667","142750197268390932384717001420957702105"],"threshold":0.9},"id":"CVE-2025-1215-e2137659","signature_type":"Line"},{"id":"CVE-2025-1215-ff55883c","signature_type":"Line","signature_version":"v1","source":"https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9","target":{"file":"src/message_test.c"},"deprecated":false,"digest":{"line_hashes":["92287973960607894250659376053288295323","132225924347105318751558682158905399951","327706802538832193745037149380504849990","23071943257264356039521028396927262525"],"threshold":0.9}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}