{"id":"CVE-2025-55157","summary":"Vim heap use-after-free vulnerability when processing recursive tuple data types","details":"Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger a use-after-free in Vim’s internal tuple reference management. Specifically, the tuple_unref() function may access already freed memory due to improper lifetime handling, leading to memory corruption. The exploit requires direct user interaction, as the script must be explicitly executed within Vim. This issue has been patched in version 9.1.1400.","aliases":["GHSA-3r4f-mm4w-wgg6"],"modified":"2026-08-12T11:38:29.178303Z","published":"2025-08-11T22:54:27.302Z","related":["SUSE-SU-2025:03240-1","SUSE-SU-2025:03299-1","SUSE-SU-2025:03300-1","SUSE-SU-2025:20696-1","SUSE-SU-2025:20857-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55157.json"},"references":[{"type":"WEB","url":"https://github.com/vim/vim/releases/tag/v9.1.1400"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55157.json"},{"type":"ADVISORY","url":"https://github.com/vim/vim/security/advisories/GHSA-3r4f-mm4w-wgg6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55157"},{"type":"FIX","url":"https://github.com/vim/vim/commit/1307743697bbc46e1518abfea7f89caa95bcaf97"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vim/vim","events":[{"introduced":"4e7b4308fb92628434bd7e07ab92910c33051431"},{"fixed":"1307743697bbc46e1518abfea7f89caa95bcaf97"}],"database_specific":{"cpe":"cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"9.1.1231"},{"fixed":"9.1.1400"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["v9.1.1399","v9.1.1398","v9.1.1397","v9.1.1396","v9.1.1395","v9.1.1394","v9.1.1393","v9.1.1391","v9.1.1390","v9.1.1389","v9.1.1388","v9.1.1387","v9.1.1386","v9.1.1385","v9.1.1384","v9.1.1383","v9.1.1382","v9.1.1381","v9.1.1380","v9.1.1379","v9.1.1378","v9.1.1377","v9.1.1376","v9.1.1375","v9.1.1374","v9.1.1373","v9.1.1372","v9.1.1371","v9.1.1370","v9.1.1369","v9.1.1368","v9.1.1367","v9.1.1366","v9.1.1365","v9.1.1364","v9.1.1363","v9.1.1362","v9.1.1361","v9.1.1360","v9.1.1359","v9.1.1358","v9.1.1357","v9.1.1356","v9.1.1355","v9.1.1354","v9.1.1353","v9.1.1352","v9.1.1351","v9.1.1350","v9.1.1349","v9.1.1348","v9.1.1347","v9.1.1346","v9.1.1345","v9.1.1344","v9.1.1343","v9.1.1342","v9.1.1341","v9.1.1340","v9.1.1339","v9.1.1338","v9.1.1337","v9.1.1336","v9.1.1335","v9.1.1334","v9.1.1333","v9.1.1332","v9.1.1331","v9.1.1330","v9.1.1329","v9.1.1328","v9.1.1327","v9.1.1326","v9.1.1325","v9.1.1324","v9.1.1323","v9.1.1322","v9.1.1321","v9.1.1320","v9.1.1319","v9.1.1318","v9.1.1317","v9.1.1316","v9.1.1315","v9.1.1314","v9.1.1313","v9.1.1312","v9.1.1311","v9.1.1310","v9.1.1309","v9.1.1308","v9.1.1307","v9.1.1306","v9.1.1305","v9.1.1304","v9.1.1303","v9.1.1302","v9.1.1301","v9.1.1300","v9.1.1299","v9.1.1298","v9.1.1297","v9.1.1296","v9.1.1295","v9.1.1294","v9.1.1293","v9.1.1292","v9.1.1291","v9.1.1290","v9.1.1289","v9.1.1288","v9.1.1287","v9.1.1286","v9.1.1285","v9.1.1284","v9.1.1283","v9.1.1282","v9.1.1281","v9.1.1280","v9.1.1279","v9.1.1278","v9.1.1277","v9.1.1276","v9.1.1275","v9.1.1274","v9.1.1273","v9.1.1272","v9.1.1271","v9.1.1270","v9.1.1269","v9.1.1268","v9.1.1267","v9.1.1266","v9.1.1265","v9.1.1264","v9.1.1263","v9.1.1262","v9.1.1261","v9.1.1260","v9.1.1259","v9.1.1258","v9.1.1257","v9.1.1256","v9.1.1255","v9.1.1254","v9.1.1253","v9.1.1252","v9.1.1251","v9.1.1250","v9.1.1249","v9.1.1248","v9.1.1247","v9.1.1246","v9.1.1245","v9.1.1244","v9.1.1243","v9.1.1242","v9.1.1241","v9.1.1240","v9.1.1239","v9.1.1238","v9.1.1237","v9.1.1236","v9.1.1235","v9.1.1234","v9.1.1233","v9.1.1232","v9.1.1231"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["149125425587941505718713537557277157561","36865772915428408168343709538823433049","41818860565170166722081033080640122526","160230890600933848206922492239307847324"],"threshold":0.9},"id":"CVE-2025-55157-0e64afba","signature_type":"Line","signature_version":"v1","source":"https://github.com/vim/vim/commit/1307743697bbc46e1518abfea7f89caa95bcaf97","target":{"file":"src/eval.c"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/vim/vim/commit/1307743697bbc46e1518abfea7f89caa95bcaf97","target":{"file":"src/version.c"},"deprecated":false,"digest":{"line_hashes":["146200493773228420153804765641940418619","110198240930994937201121759945904201354","212193721308662048981993545006333702479","283889450580603242491284889368818899009"],"threshold":0.9},"id":"CVE-2025-55157-6b1dd7f1"},{"id":"CVE-2025-55157-a7f9ed65","signature_type":"Function","signature_version":"v1","source":"https://github.com/vim/vim/commit/1307743697bbc46e1518abfea7f89caa95bcaf97","target":{"file":"src/eval.c","function":"eval9_nested_expr"},"deprecated":false,"digest":{"function_hash":"163237425320400284125946284535320468604","length":955}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55157.json","vanir_signatures_modified":"2026-08-12T11:38:29Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}