CVE-2022-3256

Executive Summary

CVE-2022-3256 is a use‑after‑free flaw in Vim (prior to 9.0.0530) that can be triggered by crafted input, potentially leading to arbitrary code execution or denial of service. The issue stems from improper memory handling during buffer operations. No current CISA KEV listing.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-09-22T13:15:09.133 - Last Modified: 2026-09-24T15:54:01.663

Original Description: Use After Free in GitHub repository vim/vim prior to 9.0.0530.

"Do, or do not. There is no try."

— Yoda
Source: NVD