Bug 33626 - vim new security issue: use-after-free when closing buffers in Vim < v9.1.0764 (CVE-2024-47814)
Summary: vim new security issue: use-after-free when closing buffers in Vim < v9.1.076...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-10-09 11:35 CEST by Nicolas Salguero
Modified: 2024-10-11 03:00 CEST (History)
3 users (show)

See Also:
Source RPM: vim-9.1.719-1.mga9.src.rpm
CVE: CVE-2024-47814
Status comment:


Attachments

Description Nicolas Salguero 2024-10-09 11:35:28 CEST
That problem was announced here:
https://www.openwall.com/lists/oss-security/2024/10/06/1
Nicolas Salguero 2024-10-09 11:36:02 CEST

Status comment: (none) => Fixed upstream in 9.1.764
Source RPM: (none) => vim-9.1.719-1.mga10.src.rpm
Whiteboard: (none) => MGA9TOO

Nicolas Salguero 2024-10-10 08:57:46 CEST

CVE: (none) => CVE-2024-47814
Summary: vim new security issue: use-after-free when closing buffers in Vim < v9.1.0764 => vim new security issue: use-after-free when closing buffers in Vim < v9.1.0764 (CVE-2024-47814)

Comment 1 Nicolas Salguero 2024-10-10 09:00:28 CEST
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Use-after-free when closing buffers in Vim < v9.1.0764. (CVE-2024-47814)

References:
https://www.openwall.com/lists/oss-security/2024/10/06/1
========================

Updated packages in core/updates_testing:
========================
vim-X11-9.1.771-1.mga9
vim-common-9.1.771-1.mga9
vim-enhanced-9.1.771-1.mga9
vim-minimal-9.1.771-1.mga9

from SRPM:
vim-9.1.771-1.mga9.src.rpm

Version: Cauldron => 9
Status comment: Fixed upstream in 9.1.764 => (none)
Source RPM: vim-9.1.719-1.mga10.src.rpm => vim-9.1.719-1.mga9.src.rpm
Assignee: bugsquad => qa-bugs
Status: NEW => ASSIGNED
Whiteboard: MGA9TOO => (none)

Comment 2 Herman Viaene 2024-10-10 11:57:40 CEST
MGA9-64 server MATE on HP-Pavillion
No installation issues.
Used dd, x, i, a, w commands on a txt file.
After closing checked with pluma, all is OK.
Good enough for me.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

katnatek 2024-10-11 00:09:51 CEST

Keywords: (none) => advisory
CC: (none) => andrewsfarm

Comment 3 Thomas Andrews 2024-10-11 01:34:03 CEST
Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 4 Mageia Robot 2024-10-11 03:00:21 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0329.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.