PT-2026-22417 · Vim+3 · Vim+3
Ehdgks0627
·
Published
2026-02-27
·
Updated
2026-05-24
·
CVE-2026-28418
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Vim versions prior to 9.2.0074
Description
Vim, an open source command line text editor, has an issue where a heap-based buffer overflow out-of-bounds read can occur in the Emacs-style tags file parsing logic. Processing a specially crafted, malformed tags file can allow an attacker to read up to 7 bytes beyond the allocated memory boundary. The issue affects the availability of protected information.
Recommendations
Versions prior to 9.2.0074 should be updated to version 9.2.0074 or later.
Exploit
Fix
DoS
Out of bounds Read
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Vim