> Source: [sk185154](https://support.checkpoint.com/results/sk/sk185154)

# sk185154 - Check Point response to Vim text editor CVEs

| Property | Value |
|----------|-------|
| Solution ID | sk185154 |
| Date Created | 2026-07-23 |
| Last Modified | 2026-08-09 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R81.20, R82 |
| OS | Gaia |

## Solution

Vim is an open-source text editor.

* The listed Vim CVEs do not require mitigation or a Hotfix.
* Do not install third-party packages on Check Point appliances to mitigate scanner findings. Third-party packages can affect supportability and system stability.

To see the Vim version, run one of these commands:  

`[Expert@Hostname]# vim --version | head -1`  
or  
`[Expert@Hostname]# vim --version | grep -i "VIM - Vi IMproved"`  

The output looks like this:  

`[Expert@Hostname]# vim --version | head -1`  
`VIM - Vi IMproved 7.0 (2006 May 7, compiled Nov 6 2012 12:37:39)`  

`[Expert@Hostname]# vim --version | grep -i "VIM - Vi IMproved"`  
`VIM - Vi IMproved 7.0 (2006 May 7, compiled Nov 6 2012 12:37:39)`  

*** ** * ** ***

|-------------------------------------------------------------------------------|-------------------------------------------------------------------------|----------------|
| **Vulnerability Name**                                                        | **CVE**                                                                 | **Status**     |
| Vim \< 9.0.1532 Code Execution                                                | [CVE-2023-2610](https://access.redhat.com/security/cve/cve-2023-2610)   | Not vulnerable |
| Vim \< 9.0.1858                                                               | [CVE-2023-4752](https://access.redhat.com/security/cve/cve-2023-4752)   | Not vulnerable |
| Vim \< 9.0.1857                                                               | [CVE-2023-4750](https://nvd.nist.gov/vuln/detail/cve-2023-4750)         | Not vulnerable |
| Vim \< 9.0.1969 Buffer Overflow DoS                                           | [CVE-2023-5344](https://access.redhat.com/security/cve/cve-2023-5344)   | Not vulnerable |
| Vim \< 9.0.2010 Use-After-Free                                                | [CVE-2023-5535](https://access.redhat.com/security/cve/cve-2023-5535)   | Not vulnerable |
| Vim \< 9.2.0202 Command Injection (GHSA-w5jw-f54h-x46c)                       | [CVE-2026-33412](https://access.redhat.com/security/cve/cve-2026-33412) | Not vulnerable |
| Vim \< 9.2.0316 Command Injection (GHSA-mr87-rhgv-7pw6)                       | [CVE-2026-39881](https://access.redhat.com/security/cve/cve-2026-39881) | Not vulnerable |
| Vim \< 9.2.0597 Code Execution (GHSA-65p9-mwwx-7468)                          | [CVE-2026-52860](https://access.redhat.com/security/cve/cve-2026-52860) | Not vulnerable |
| Vim \< 9.2.0561 Code Injection (GHSA-52mc-rq6p-rc7c)                          | [CVE-2026-52858](https://nvd.nist.gov/vuln/detail/CVE-2026-52858)       | Not vulnerable |
| Vim \< 9.0.1499 DoS                                                           | [CVE-2023-2426](https://access.redhat.com/security/cve/cve-2023-2426)   | Not vulnerable |
| Vim \< 9.0.1992 NULL Pointer Dereference                                      | [CVE-2023-5441](https://access.redhat.com/security/cve/cve-2023-5441)   | Not vulnerable |
| Vim \< 9.0.2068 Use After Free                                                | [CVE-2023-46246](https://nvd.nist.gov/vuln/detail/CVE-2023-46246)       | Not vulnerable |
| Vim \< 9.0.2106                                                               | [CVE-2023-48231](https://nvd.nist.gov/vuln/detail/CVE-2023-48231)       | Not vulnerable |
| Vim \< 9.0.2107                                                               | [CVE-2023-48232](https://access.redhat.com/security/cve/cve-2023-48232) | Not vulnerable |
| Vim \< 9.0.2110                                                               | [CVE-2023-48235](https://access.redhat.com/security/cve/cve-2023-48235) | Not vulnerable |
| Vim \< 9.0.2108                                                               | [CVE-2023-48233](https://access.redhat.com/security/cve/cve-2023-48233) | Not vulnerable |
| Vim \< 9.0.2121                                                               | [CVE-2023-48706](https://nvd.nist.gov/vuln/detail/cve-2023-48706)       | Not vulnerable |
| Vim \< 9.0.2109                                                               | [CVE-2023-48234](https://nvd.nist.gov/vuln/detail/CVE-2023-48234)       | Not vulnerable |
| Vim \< 9.1.0647 Use-After-Free                                                | [CVE-2024-41957](https://access.redhat.com/security/cve/CVE-2024-41957) | Not vulnerable |
| Vim \< 9.1.0648 Double-Free                                                   | [CVE-2024-41965](https://access.redhat.com/security/cve/cve-2024-41965) | Not vulnerable |
| Vim \< 9.1.0678 Heap-Use                                                      | [CVE-2024-43374](https://access.redhat.com/security/cve/CVE-2024-43374) | Not vulnerable |
| Vim \< 9.1.0697 Heap Buffer Overflow \& Vim 9.1.0764 (GHSA-rj48-v4mq-j4vg)    | [CVE-2024-43802](https://access.redhat.com/security/cve/cve-2024-43802) | Not vulnerable |
| Vim 9.1.1003 (GHSA-5rgf-26wj-48v8)                                            | [CVE-2025-22134](https://access.redhat.com/security/cve/cve-2025-22134) | Not vulnerable |
| Vim \< 9.1.1043 Out-of-bounds Write                                           | [CVE-2025-24014](https://access.redhat.com/security/cve/cve-2025-24014) | Not vulnerable |
| Vim \< 9.1.1198 Argument Injection (GHSA-693p-m996-3rmf)                      | [CVE-2025-29768](https://access.redhat.com/security/cve/cve-2025-29768) | Not vulnerable |
| Vim \< 9.2.0074 Heap-based Buffer Overflow (GHSA-h4mf-vg97-hj8j)              | [CVE-2026-28418](https://access.redhat.com/security/cve/cve-2026-28418) | Not vulnerable |
| Vim \< 9.2.0076 Heap-based Buffer Overflow and OOB Read (GHSA-rvj2-jrf9-2phg) | [CVE-2026-28420](https://access.redhat.com/security/cve/cve-2026-28420) | Not vulnerable |
| Vim \< 9.2.0496 Code Injection (GHSA-4473-94jm-w5x9)                          | [CVE-2026-47167](https://access.redhat.com/errata/RHSA-2026:38510)      | Not vulnerable |
| Vim \< 9.2.0565 Out-of-Bounds Read (GHSA-47gw-8gc3-mgcm)                      | [CVE-2026-52859](https://access.redhat.com/security/cve/cve-2026-52859) | Not vulnerable |
| Vim \< 9.1.1097 memory corruption vulnerability                               | [CVE-2025-1215](https://access.redhat.com/errata/RHSA-2025:1215)        | Not vulnerable |
| Vim \< 9.2.0663 Code Injection (GHSA-vhh8-v6wx-hjjh)                          | [CVE-2026-55895](https://access.redhat.com/security/cve/cve-2026-55895) | Not vulnerable |
| Vim \< 9.2.0671 Out-of-Bounds Read (GHSA-c4j9-wr9j-4486)                      | [CVE-2026-57452](https://access.redhat.com/security/cve/cve-2026-57452) | Not vulnerable |
| Vim 9.1.0764 (GHSA-rj48-v4mq-j4vg)                                            | [CVE-2024-47814](https://access.redhat.com/security/cve/cve-2024-47874) | Not vulnerable |
| Vim \< 9.1.1097 memory corruption vulnerability                               | [CVE-2025-1215](https://access.redhat.com/errata/RHSA-2025:1215)        | Not vulnerable |
| Vim \< 9.2.0662 Stack Out-of-Bounds Write (GHSA-qm9w-fmpj-879h)               | [CVE-2026-55892](https://access.redhat.com/security/cve/cve-2026-55892) | Not vulnerable |
| Vim \< 9.2.0653 Stack Out-of-Bounds Write (GHSA-wgh4-64f7-q3jq)               | [CVE-2026-55693](https://access.redhat.com/errata/RHSA-2026:30267.html) | Not vulnerable |
| Vim \< 9.2.0078 Stack-Buffer-Overflow (GHSA-gmqx-prf2-8mwf)                   | [CVE-2026-28422](https://access.redhat.com/security/cve/cve-2026-28422) | Not vulnerable |

**Legend:**

|--------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Status**         | **Meaning**                                                                                                                                                                                                                                                         |
| **Not vulnerable** | The status applies when one of these is true: * The issue is not relevant to Check Point code, because the affected code does not exist or is not used in Check Point software. * The issue was relevant to Check Point code, but Check Point has already fixed it. |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
