{"id":"CVE-2022-3134","title":"Use After Free in GitHub repository vim/vim prior to 9.0.0389.","summary":"Use After Free in GitHub repository vim/vim prior to 9.0.0389.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-416","CWE-416"],"vendor":"neovim","product":"neovim","affected":["neovim >= 0.5.0, < 0.9.0","vim < 9.0.0389","debian_linux = 10.0","debian_linux = 11.0"],"patched":["neovim 0.9.0","vim 9.0.0389"],"published":"2022-09-06","updated":"2026-09-24","sourceUpdated":"2026-09-24T15:53:08.370","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-3134","references":[{"url":"https://github.com/vim/vim/commit/ccfde4d028e891a41e3548323c3d47b06fb0b83e","label":"security@huntr.dev"},{"url":"https://huntr.dev/bounties/6ec79e49-c7ab-4cd6-a517-e7934c2eb9dc","label":"security@huntr.dev"},{"url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html","label":"security@huntr.dev"},{"url":"https://security.gentoo.org/glsa/202305-16","label":"security@huntr.dev"},{"url":"https://github.com/vim/vim/commit/ccfde4d028e891a41e3548323c3d47b06fb0b83e","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://huntr.dev/bounties/6ec79e49-c7ab-4cd6-a517-e7934c2eb9dc","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00009.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00023.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202305-16","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00561,"epssPercentile":0.45478,"ingestedAt":"2026-09-24T16:47:15.804Z","slug":"CVE-2022-3134","body":"## Overview\n\nUse After Free in GitHub repository vim/vim prior to 9.0.0389.\n\n## Affected\n\n- `neovim >= 0.5.0, < 0.9.0`\n- `vim < 9.0.0389`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `neovim 0.9.0`\n- `vim 9.0.0389`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}