PT-2026-70247 · Vim+2 · Vim+2
CVE-2026-73071
·
Published
2026-08-11
·
Updated
2026-08-30
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vim versions 9.2.0511 through 9.2.0843
Description
The
json decode item() function in src/json.c can retain a stale pointer after json decode string() calls channel fill() to refill and free the current buffer. This occurs when an invalid JSON string spans buffers, causing the error path to read freed memory instead of reader->js buf + reader->js used.Recommendations
Update to version 9.2.0844.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Vim