PatchSiren cyber security CVE debrief
CVE-2017-6350 Vim CVE debrief
CVE-2017-6350 is a critical Vim vulnerability affecting versions through 8.0.0377. According to NVD and the vendor-linked patch reference, an integer overflow in unserialize_uep can occur when Vim fails to validate tree length values while reading a corrupted undo file, which may lead to buffer overflows. The vulnerability was publicly recorded on 2017-02-27, and the NVD entry was later modified on 2026-05-13; that later date reflects record maintenance, not the original issue date.
- Vendor
- Vim
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-27
- Advisory updated
- 2026-05-13
Who should care
Administrators, Linux distribution maintainers, and anyone deploying or packaging Vim should care, especially if users may open untrusted or corrupted undo files. Security teams responsible for editor packages and workstation baselines should verify patched builds.
Technical summary
NVD classifies the flaw as CWE-190 (integer overflow) with CVSS 3.0 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue is described as an insufficient validation problem in unserialize_uep's memory allocation path while processing tree-length data from a corrupted undo file. The affected CPE range in the record ends at Vim 8.0.0377, and the referenced fix is the upstream Vim commit 0c8485f0e4931463c0f7986e1ea84a7d79f10c75.
Defensive priority
High. This is a critical-severity memory corruption issue with a vendor-linked upstream fix and distro advisories. Prioritize patching or upgrading Vim wherever untrusted undo files might be encountered.
Recommended defensive actions
- Upgrade Vim to a version that includes the upstream fix referenced by commit 0c8485f0e4931463c0f7986e1ea84a7d79f10c75, or ensure the package version is newer than 8.0.0377.
- Verify enterprise package repositories and workstation images for affected Vim builds and replace any version at or below 8.0.0377.
- Apply vendor or distribution security updates referenced in the advisory trail, including Gentoo GLSA 201706-26 and Ubuntu USN-4309-1 where applicable.
- Restrict or review handling of untrusted or corrupted undo files in environments where editor inputs may come from external sources.
- Add vulnerability management checks for Vim package versions to prevent reintroduction of vulnerable builds.
Evidence notes
This debrief is based on the supplied NVD record and its cited references. The key factual anchors are: the CVE description, the CVSS 3.0 vector and score, the CWE-190 classification, the affected version range ending at 8.0.0377, and the upstream patch commit reference. No exploit steps or reproduction guidance are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6350 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6350
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6350 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6350
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/vim/vim/commit/0c8485f0e4931463c0f7986e1ea84a7d79f10c75
[email protected] - Patch, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://groups.google.com/forum/
-
Source reference
Unverified legacy reference
URL: https://groups.google.com/forum/
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201706-26
-
Source reference
Unverified legacy reference
URL: https://usn.ubuntu.com/4309-1/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.