PT-2026-70248 · Vim+3 · Vim+3
CVE-2026-73072
·
Published
2026-08-11
·
Updated
2026-09-10
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0846
Description
The
set sofo() function in src/spellfile.c reuses the sl sal first[] array without resetting values previously set by set sal first(). A specially crafted spell file containing an SN SAL section before an SN SOFO section can lead to under-counted mapping lists and allow attacker-influenced writes beyond a heap allocation, which is a memory corruption issue where data is written outside the boundaries of a pre-allocated memory block on the heap.Recommendations
Update to version 9.2.0846.
Exploit
Fix
DoS
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim