PT-2026-52477 · Vim+3 · Vim+3

·

CVE-2026-57452

·

Published

2026-06-17

·

Updated

2026-08-19

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0671
Description When opening a file encrypted using the VimCrypt04! or VimCrypt05! methods (which utilize xchacha20poly1305 and require the +sodium feature), an unsigned length calculation underflows if the file body is shorter than a single libsodium secretstream header. This leads to a decryption call that reads beyond the end of the input buffer, resulting in a crash of the application.
Recommendations Update to version 9.2.0671.

Exploit

Fix

DoS

Integer Underflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91098
BDU:2026-14502
CVE-2026-57452
ECHO-36E6-1A60-39DB
GHSA-C4J9-WR9J-4486
OESA-2026-3027
USN-8500-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim