PT-2026-70249 · Vim+3 · Vim+3
CVE-2026-73074
·
Published
2026-08-11
·
Updated
2026-09-08
CVSS v4.0
7.1
High
| Vector | AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0841
Description
The
prop add one() function in src/textprop.c uses the proplen value from get text props() to increment a uint16 t property count. If the count exceeds 0xffff, it wraps around to zero, leading to a heap allocation that is too small for the existing text-property records being copied into it.Recommendations
Update to version 9.2.0841.
Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim