---
id: CVE-2023-46246
title: Vim is an improved version of the good old UNIX editor Vi
summary: >-
  Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free
  in memory allocated in the function `ga_grow_inner` in in the file
  `src/alloc.c` at line 748, which is freed in the file `src/ex_docmd.c` in the
  function `do_…
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-190
  - CWE-416
  - CWE-190
  - CWE-416
vendor: vim
product: vim
affected:
  - vim < 9.0.2068
patched:
  - vim 9.0.2068
published: '2023-10-27'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-46246'
references:
  - url: 'https://github.com/vim/vim/commit/9198c1f2b1ddecde22af918541e0de2a32f0f45a'
    label: security-advisories@github.com
  - url: 'https://github.com/vim/vim/security/advisories/GHSA-q22m-h7m2-9mgm'
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNMFS3IH74KEMMESOA3EOB6MZ56TWGFF/
    label: security-advisories@github.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IVA7K73WHQH4KVFDJQ7ELIUD2WK5ZT5E/
    label: security-advisories@github.com
  - url: 'https://security.netapp.com/advisory/ntap-20231208-0006/'
    label: security-advisories@github.com
  - url: 'https://github.com/vim/vim/commit/9198c1f2b1ddecde22af918541e0de2a32f0f45a'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/vim/vim/security/advisories/GHSA-q22m-h7m2-9mgm'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DNMFS3IH74KEMMESOA3EOB6MZ56TWGFF/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IVA7K73WHQH4KVFDJQ7ELIUD2WK5ZT5E/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20231208-0006/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00366
epssPercentile: 0.30512
ingestedAt: '2026-06-29T13:24:33.921Z'
---

## Overview

Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/alloc.c` at line 748, which is freed in the file `src/ex_docmd.c` in the function `do_cmdline` at line 1010 and then used again in `src/cmdhist.c` at line 759. When using the `:history` command, it's possible that the provided argument overflows the accepted value. Causing an Integer Overflow and potentially later an use-after-free. This vulnerability has been patched in version 9.0.2068.

## Affected

- `vim < 9.0.2068`

## Remediation

Upgrade past the affected range:

- `vim 9.0.2068`
