PT-2026-70249 · Vim+3 · Vim+3

CVE-2026-73074

·

Published

2026-08-11

·

Updated

2026-09-08

CVSS v4.0

7.1

High

VectorAV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0841
Description The prop add one() function in src/textprop.c uses the proplen value from get text props() to increment a uint16 t property count. If the count exceeds 0xffff, it wraps around to zero, leading to a heap allocation that is too small for the existing text-property records being copied into it.
Recommendations Update to version 9.2.0841.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95553
CVE-2026-73074
ECHO-82D9-53FE-5993
GHSA-HM4G-PJFX-M27J
OESA-2026-3555
OPENSUSE-SU-2026:21671-1
SUSE-SU-2026:23190-1
SUSE-SU-2026:23365-1
SUSE-SU-2026:23391-1
SUSE-SU-2026:23393-1
SUSE-SU-2026:3677-1
SUSE-SU-2026:3679-1
SUSE-SU-2026:3680-1
USN-8657-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim