PT-2026-52480 · Vim+4 · Vim+4
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0698
Description
A stack out-of-bounds write occurs in the single-byte branch of the
spell soundfold sofo() function within src/spell.c. When a SOFO-based spell language is active, the copy loop translates a word using a sound-folding (SOFO) byte map into a caller-owned result buffer. Because the output index ri advances without an upper bound and only terminates on the input NUL, any word longer than the MAXWLEN-element stack buffer will write past the buffer's end. This corrupts the call frame and causes the editor to crash. This issue can be triggered when a word exceeding MAXWLEN is passed to soundfold() or reached via sound-based spell suggestions.Recommendations
Update to version 9.2.0698.
Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Ubuntu
Vim