Vim · Vim · CVE-2026-57454
**Name of the Vulnerable Software and Affected Versions**
Vim versions 9.2.0320 through 9.2.0678
**Description**
A flaw exists where a crafted undo or swap file can store a virtual-text property with an offset and length that point outside the line's property data. When the software restores or displays such a line, it converts the offset into a pointer and reads the virtual text without bounds checking. This results in an out-of-bounds read, which may lead to a crash or the disclosure of adjacent heap memory.
**Recommendations**
Update to version 9.2.0679.