CVE-2022-3134

Executive Summary

CVE-2022-3134 is a use‑after‑free vulnerability in Vim (versions <9.0.0389) that can be triggered by crafted input, allowing an attacker to read or corrupt memory, potentially leading to arbitrary code execution or denial of service. The flaw arises from improper deallocation of a buffer during command processing. No patch is currently listed in CISA KEV, but users should upgrade to 9.0.0389 or later.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-09-06T20:15:09.150 - Last Modified: 2026-09-24T15:53:08.370

Original Description: Use After Free in GitHub repository vim/vim prior to 9.0.0389.

"While we stop to think, we often miss our opportunity."

— Publilius Syrus
Source: NVD