PT-2026-70250 · Vim · Vim

CVE-2026-73075

·

Published

2026-08-11

·

Updated

2026-08-28

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Vim versions 9.2.0469 through 9.2.0842
Description The popup mark opacity zindex() function in src/popupwin.c can use a negative w winrow for a text-property-anchored popup with clipwindow and opacity. This leads to indexing before the screen array instead of accounting for w popup topoff, resulting in an out-of-bounds read and conditional write.
Recommendations Update to version 9.2.0843.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95973
CVE-2026-73075
GHSA-PMVP-6RCJ-98P4
OPENSUSE-SU-2026:21671-1
SUSE-SU-2026:23190-1
SUSE-SU-2026:23365-1
SUSE-SU-2026:23391-1
SUSE-SU-2026:23393-1
SUSE-SU-2026:3677-1
SUSE-SU-2026:3679-1
SUSE-SU-2026:3680-1

Affected Products

Vim