CVE-2022-3297

Executive Summary

CVE-2022-3297 is a use‑after‑free vulnerability in Vim (prior to 9.0.0579) that can lead to memory corruption and potentially arbitrary code execution when a malicious file is opened. The flaw arises from improper handling of freed memory during buffer manipulation, allowing an attacker to craft input that triggers the vulnerability. No current CISA KEV listing, but the issue is publicly disclosed and mitigated by updating to Vim 9.0.0579 or later.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-09-25T19:15:09.673 - Last Modified: 2026-09-24T15:38:08.260

Original Description: Use After Free in GitHub repository vim/vim prior to 9.0.0579.

"If one advances confidently in the direction of his dream, and endeavours to live the life which he had imagines, he will meet with a success unexpected in common hours."

— Henry David Thoreau
Source: NVD