PT-2026-70246 · Vim+1 · Vim+1

CVE-2026-73070

·

Published

2026-08-11

·

Updated

2026-09-08

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0842
Description The socket server backend in src/socketserver.c accepts unbounded client connections in the socketserver accept() function. This behavior causes descriptors to overflow fd set structures in src/channel.c and fixed-size struct pollfd arrays in src/os unix.c. Consequently, a local process capable of connecting to the server socket can corrupt stack memory or terminate the Vim server.
Recommendations Update to version 9.2.0842.

Exploit

Fix

DoS

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95565
CVE-2026-73070
ECHO-9C0F-ED25-4506
GHSA-49M8-WWXJ-MR69
OPENSUSE-SU-2026:21671-1
RHSA-2026:56636
SUSE-SU-2026:23190-1
SUSE-SU-2026:23365-1
SUSE-SU-2026:23391-1
SUSE-SU-2026:23393-1
SUSE-SU-2026:3677-1
SUSE-SU-2026:3679-1
SUSE-SU-2026:3680-1

Affected Products

Red Os
Vim