PT-2026-39222 · Vim+3 · Vim+3

·

CVE-2026-45130

·

Published

2026-05-07

·

Updated

2026-06-29

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0450
Description A heap buffer overflow occurs in the read compound() function within src/spellfile.c when loading a specially crafted spell file (.spl) while UTF-8 encoding is active. An attacker-controlled length field in the compound section of the spell file causes a 32-bit signed integer multiplication overflow. This results in the allocation of an undersized buffer for a write loop that executes numerous iterations, leading to a heap overflow. This process can be triggered via a text file modeline that sets the spelllang option, provided a malicious .spl file is present on the runtimepath.
Recommendations Update to version 9.2.0450.

Exploit

Fix

DoS

Integer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86246
BDU:2026-09627
CVE-2026-45130
ECHO-DAD7-435C-45C4
GHSA-Q4JV-R9GJ-6CWV
OESA-2026-2447
OESA-2026-2448
OESA-2026-2449
OESA-2026-2450
OESA-2026-2472
OPENSUSE-SU-2026:11114-1
OPENSUSE-SU-2026:20828-1
SUSE-SU-2026:21833-1
SUSE-SU-2026:21840-1
SUSE-SU-2026:21859-1
SUSE-SU-2026:21880-1
SUSE-SU-2026:21944-1
SUSE-SU-2026:2233-1
SUSE-SU-2026:2236-1
SUSE-SU-2026:2313-1
USN-8304-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim