CVE-2025-9389

Source
https://cve.org/CVERecord?id=CVE-2025-9389
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9389.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-9389
Downstream
Published
2025-08-24T13:02:07.721Z
Modified
2026-07-18T03:45:51.098560417Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
vim memmove-vec-unaligned-erms.S __memmove_avx_unaligned_erms memory corruption
Details

A vulnerability was identified in vim 9.1.0000. Affected is the function _memmoveavxunalignederms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publicly available and might be used. Some users are not able to reproduce this. One of the users mentions that this appears not to be working, "when coloring is turned on".

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9389.json",
    "cwe_ids": [
        "CWE-119"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/vim/vim

Affected ranges

Type
GIT
Repo
https://github.com/vim/vim
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "9.1.0000"
        },
        {
            "last_affected": "9.1.0000"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ],
    "cpe": "cpe:2.3:a:vim:vim:9.1.0000:*:*:*:*:*:*:*"
}

Affected versions

9.*
9.1.0000

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9389.json"