CVE-2026-57452

EUVD-2026-39448
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05!
method (xchacha20poly1305, requires the +sodium feature) whose body is shorter than a single libsodium secretstream header, an unsigned length calculation underflows and a subsequent decryption call reads far past the end of the input buffer, crashing Vim. This vulnerability is fixed in 9.2.0671.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.97%
Affected Products (NVD)
VendorProductVersion
vimvim
𝑥
< 9.2.0671
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
vim
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
2:9.2.0858-1
fixed
sid
2:9.2.0858-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vim
bionic
not-affected
focal
not-affected
jammy
Fixed 2:8.2.3995-1ubuntu2.33
released
noble
Fixed 2:9.1.0016-1ubuntu7.17
released
questing
Fixed 2:9.1.0967-1ubuntu6.8
released
resolute
Fixed 2:9.1.2141-1ubuntu4.6
released
trusty
not-affected
xenial
not-affected
Azure Linux logo
Azure Linux Releases
Azure Package
Release
vim
Azure Linux 3.0
0:9.2.0735-1.azl3
fixed