Amazon Linux 2023 Security Advisory: ALAS-2024-761
Advisory Release Date: 2024-11-13 12:28 Pacific
Advisory Updated Date: 2024-11-14 11:00 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags,
but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647 (CVE-2024-41957)
The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678. (CVE-2024-43374)
Vim is an improved version of the unix vi text editor. When flushing the typeahead buffer, Vim moves the current position in the typeahead buffer but does not check whether there is enough space left in the buffer to handle the next characters. So this may lead to the tb_off position within the typebuf variable to point outside of the valid buffer size, which can then later lead to a heap-buffer overflow in e.g. ins_typebuf(). Therefore, when flushing the typeahead buffer, check if there is enough space left before advancing the off position. If not, fall back to flush current typebuf contents. It's not quite clear yet, what can lead to this situation. It seems to happen when error messages occur (which will cause Vim to flush the typeahead buffer) in comnination with several long mappgins and so it may eventually move the off position out of a valid buffer size. Impact is low since it is not easily reproducible and requires to have several mappings active and run into some error condition. But when this happens, this will cause a crash. The issue has been fixed as of Vim patch v9.1.0697. Users are advised to upgrade. There are no known workarounds for this issue. (CVE-2024-43802)
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact is low since the user must have intentionally set up such a strange auto command and run some buffer unload commands. However this may lead to a crash. This issue has been addressed in version 9.1.0764 and all users are advised to upgrade. There are no known workarounds for this vulnerability. (CVE-2024-47814)
Affected Packages:
vim
Issue Correction:
Run dnf update vim --releasever 2023.6.20241111 to update your system.
aarch64:
vim-enhanced-debuginfo-9.1.785-1.amzn2023.0.1.aarch64
vim-minimal-debuginfo-9.1.785-1.amzn2023.0.1.aarch64
vim-minimal-9.1.785-1.amzn2023.0.1.aarch64
xxd-9.1.785-1.amzn2023.0.1.aarch64
vim-debuginfo-9.1.785-1.amzn2023.0.1.aarch64
vim-enhanced-9.1.785-1.amzn2023.0.1.aarch64
vim-debugsource-9.1.785-1.amzn2023.0.1.aarch64
xxd-debuginfo-9.1.785-1.amzn2023.0.1.aarch64
vim-common-9.1.785-1.amzn2023.0.1.aarch64
noarch:
vim-default-editor-9.1.785-1.amzn2023.0.1.noarch
vim-data-9.1.785-1.amzn2023.0.1.noarch
vim-filesystem-9.1.785-1.amzn2023.0.1.noarch
src:
vim-9.1.785-1.amzn2023.0.1.src
x86_64:
vim-enhanced-debuginfo-9.1.785-1.amzn2023.0.1.x86_64
vim-minimal-debuginfo-9.1.785-1.amzn2023.0.1.x86_64
vim-minimal-9.1.785-1.amzn2023.0.1.x86_64
xxd-9.1.785-1.amzn2023.0.1.x86_64
vim-debugsource-9.1.785-1.amzn2023.0.1.x86_64
vim-enhanced-9.1.785-1.amzn2023.0.1.x86_64
xxd-debuginfo-9.1.785-1.amzn2023.0.1.x86_64
vim-debuginfo-9.1.785-1.amzn2023.0.1.x86_64
vim-common-9.1.785-1.amzn2023.0.1.x86_64