PT-2026-70247 · Vim+2 · Vim+2

CVE-2026-73071

·

Published

2026-08-11

·

Updated

2026-08-30

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vim versions 9.2.0511 through 9.2.0843
Description The json decode item() function in src/json.c can retain a stale pointer after json decode string() calls channel fill() to refill and free the current buffer. This occurs when an invalid JSON string spans buffers, causing the error path to read freed memory instead of reader->js buf + reader->js used.
Recommendations Update to version 9.2.0844.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95976
CVE-2026-73071
GHSA-69CH-22CH-R887
OESA-2026-3555
OPENSUSE-SU-2026:21671-1
SUSE-SU-2026:23190-1
SUSE-SU-2026:23365-1
SUSE-SU-2026:23391-1
SUSE-SU-2026:23393-1
SUSE-SU-2026:3677-1
SUSE-SU-2026:3679-1
SUSE-SU-2026:3680-1
USN-8657-1

Affected Products

Linuxmint
Ubuntu
Vim