CVE-2024-41957

MEDIUM
Published Aug 1, 2024 Modified Nov 4, 2025 CWE-415

Description

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647

Is your site exposed to CVE-2024-41957?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

4.5
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L

Weakness Type (CWE)

CWE-415 CWE-415

Affected Products

Vendor Product
vim vim

References

Frequently Asked Questions

What is CVE-2024-41957? +
Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in a double-free/use-after-free access exception. Impact is low since the user must intentionally execute vim with several non-default flags, but it may cause a crash of Vim. The issue has been fixed as of Vim patch v9.1.0647 It has a CVSS v3.1 base score of 4.5 (MEDIUM).
How severe is CVE-2024-41957? +
CVE-2024-41957 has a CVSS v3.1 score of 4.5 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-41957? +
CVE-2024-41957 affects products from vim, specifically: vim. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-41957? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-41957 — free, no signup required.