PT-2026-52472 · Vim+4 · Vim+4

·

CVE-2026-55693

·

Published

2026-06-15

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0653
Description The tree count words() function in src/spellfile.c fails to validate a depth counter against the size of fixed MAXWLEN-element stack arrays, specifically arridx[], curi[], and wordcount[]. A specially crafted .spl/.sug file pair can trigger an arbitrarily deep descent during spell suggestion, resulting in a stack out-of-bounds write. This memory corruption affects the call frame and leads to an application crash.
Recommendations Update to version 9.2.0653.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47982
ALSA-2026:48650
ALSA-2026:48703
AZL-91107
BDU:2026-14509
CVE-2026-55693
ECHO-31D3-7C0E-C6D2
GHSA-WGH4-64F7-Q3JQ
OESA-2026-2862
OESA-2026-2904
OESA-2026-2905
OESA-2026-2906
RHSA-2026:30267
RHSA-2026:47982
RHSA-2026:48650
RHSA-2026:48703
USN-8500-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim