CVE-2026-32249
EUVD-2026-1169012.03.2026, 20:16
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits the composing bytes of that character as separate NFA states. This corrupts the NFA postfix stack, resulting in NFA_START_COLL having a NULL out1 pointer. When nfa_max_width() subsequently traverses the compiled NFA to estimate match width for the look-behind assertion, it dereferences state->out1->out without a NULL check, causing a segmentation fault. This vulnerability is fixed in 9.2.0137.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vim | vim | 9.1.0011 ≤ 𝑥 < 9.1.0137 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| vim-common |
| ||
| vim-data |
| ||
| vim-debuginfo |
| ||
| vim-debugsource |
| ||
| vim-default-editor |
| ||
| vim-enhanced |
| ||
| vim-enhanced-debuginfo |
| ||
| vim-filesystem |
| ||
| vim-minimal |
| ||
| vim-minimal-debuginfo |
| ||
| xxd |
| ||
| xxd-debuginfo |
|
Azure Linux Releases
Common Weakness Enumeration