Cyber Resilience

CVE-2023-48232

Fedoraproject Fedora 37 … 39

Published
16 November 2023
Modified
23 June 2026
Patch / advisory
CVSS Score v3.1 3.9
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
EPSS Score 0.0067 48th percentile
Risk Priority 22 floored blend · peak EPSS

Summary

CVE-2023-48232 is a low-severity Improper Handling of Exceptional Conditions (CWE-755) vulnerability in Fedoraproject Fedora. Its CVSS base score is 3.9 (Low).

Operationally, ranked at the 48th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability Data

Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may happen when a…

more

window border is present and when the wrapped line continues on the next physical line directly in the window border because the 'cpo' setting includes the 'n' flag. Only users with non-default settings are affected and the exception should only result in a crash. This issue has been addressed in commit `cb0b99f0` which has been included in release version 9.0.2107. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-22667Same product: Fedoraproject Fedora
CVE-2023-5535Same product: Fedoraproject Fedora
CVE-2023-48237Same product: Fedoraproject Fedora
CVE-2023-48234Same product: Fedoraproject Fedora
CVE-2023-5344Same product: Fedoraproject Fedora
CVE-2023-5441Same product: Fedoraproject Fedora
CVE-2023-48233Same product: Fedoraproject Fedora
CVE-2023-2609Same product: Fedoraproject Fedora
CVE-2023-0049Same product: Fedoraproject Fedora
CVE-2023-48235Same product: Fedoraproject Fedora

Affected Assets

vim
vim
≤ 9.0.2107
fedoraproject
fedora
37, 38, 39

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-755

Provides defined handling (alert and additional actions) for the exceptional condition of audit logging failure.

addresses: CWE-755

Supplies a concrete handling action (safe mode) for exceptional conditions, mitigating risks from improper or absent handling that could allow continued attacks.

addresses: CWE-755

By preparing users for contingency scenarios, the control promotes proper handling of exceptional conditions instead of default or unsafe behaviors.

addresses: CWE-755

An updated contingency plan defines current actions for exceptional conditions, reducing the window for attackers to exploit improper handling leading to system failure.

addresses: CWE-755

Procedures ensure proper handling of exceptional conditions to support effective incident response.

addresses: CWE-755

Incident response testing confirms proper handling of exceptional conditions to limit exploit impact.

addresses: CWE-755

Gives users guidance on incident handling, reducing improper handling of exceptional conditions that could stem from exploited weaknesses.

addresses: CWE-755

Enforces structured response to exceptional conditions so the system cannot remain in an unsafe state.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices explicitly require proper exception and error handling during design and coding.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

detects

Security testing in development and acceptance verifies correct handling of exceptional conditions.

degrades

Documented operating procedures may specify exception handling but do not guarantee implementation.

A.8.15 Logging partial match
detects

Logging captures unhandled exceptions, aiding detection but not preventing the weakness.

detects

Monitoring can surface unhandled exceptions but does not enforce proper handling.

prevents

Secure SDLC mandates exception-handling requirements and testing that directly prevent improper handling of exceptional conditions.

prevents

Application security requirements explicitly include handling of error and exceptional conditions.

References