PT-2026-22417 · Vim+3 · Vim+3

Ehdgks0627

·

Published

2026-02-27

·

Updated

2026-05-24

·

CVE-2026-28418

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0074
Description Vim, an open source command line text editor, has an issue where a heap-based buffer overflow out-of-bounds read can occur in the Emacs-style tags file parsing logic. Processing a specially crafted, malformed tags file can allow an attacker to read up to 7 bytes beyond the allocated memory boundary. The issue affects the availability of protected information.
Recommendations Versions prior to 9.2.0074 should be updated to version 9.2.0074 or later.

Exploit

Fix

DoS

Out of bounds Read

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-78506
BDU:2026-02590
CVE-2026-28418
ECHO-2FE0-BD26-F8D7
GHSA-H4MF-VG97-HJ8J
MGASA-2026-0049
OESA-2026-1565
SUSE-SU-2026:0910-1
SUSE-SU-2026:1051-1
SUSE-SU-2026:1095-1
USN-8101-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim