CVE-2026-57454
EUVD-2026-3944125.06.2026, 16:16
Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose offset and length point outside the line's property data. When Vim restores or displays such a line it converts the offset into a pointer and reads the virtual text without bounds checking, causing an out-of-bounds read that can crash Vim or disclose adjacent heap memory. This vulnerability is fixed in 9.2.0679.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vim | vim | 9.2.0320 ≤ 𝑥 < 9.2.0679 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| vim-common |
| ||
| vim-data |
| ||
| vim-debuginfo |
| ||
| vim-debugsource |
| ||
| vim-default-editor |
| ||
| vim-enhanced |
| ||
| vim-enhanced-debuginfo |
| ||
| vim-filesystem |
| ||
| vim-minimal |
| ||
| vim-minimal-debuginfo |
| ||
| xxd |
| ||
| xxd-debuginfo |
|
Common Weakness Enumeration