PT-2026-52479 · Vim+1 · Vim+1

·

CVE-2026-57454

·

Published

2026-06-20

·

Updated

2026-08-19

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vim versions 9.2.0320 through 9.2.0678
Description A flaw exists where a crafted undo or swap file can store a virtual-text property with an offset and length that point outside the line's property data. When the software restores or displays such a line, it converts the offset into a pointer and reads the virtual text without bounds checking. This results in an out-of-bounds read, which may lead to a crash or the disclosure of adjacent heap memory.
Recommendations Update to version 9.2.0679.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91122
BDU:2026-14500
CVE-2026-57454
GHSA-WW8H-47XP-HP4W

Affected Products

Red Os
Vim