CVE-2024-22667: Fedoraproject Fedora

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.

Affected products

  • Fedoraproject Fedora: version 38 only; version 39 only
  • Vim Vim: before 9.0.2142 (fixed in 9.0.2142)

Published 2024-02-05. Last modified 2026-06-17.