CVE-2025-9389

EUVD-2025-25742
A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Affected Products (NVD)
VendorProductVersion
vimvim
9.1.0000
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
vim
bookworm
2:9.0.1378-2+deb12u2
fixed
bullseye
2:8.2.2434-3+deb11u1
fixed
bullseye (security)
2:8.2.2434-3+deb11u3
fixed
forky
2:9.2.0524-1
fixed
sid
2:9.2.0782-1
fixed
trixie
2:9.1.1230-2
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
vim-common
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-data
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-debuginfo
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-debugsource
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-default-editor
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-enhanced
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-enhanced-debuginfo
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-filesystem
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-minimal
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
vim-minimal-debuginfo
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
xxd
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed
xxd-debuginfo
Amazon Linux 2023
2:9.2.240-1.amzn2023.0.2
fixed