PT-2026-22418 · Vim+3 · Vim+3

·

CVE-2026-28419

·

Published

2026-02-27

·

Updated

2026-06-26

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0075
Description Vim, an open source command line text editor, contains a heap-based buffer underflow issue in its Emacs-style tags file parsing logic. When processing a malformed tags file containing a delimiter at the start of a line, Vim attempts to read memory before the allocated buffer. This can potentially lead to a denial-of-service condition.
Recommendations Versions prior to 9.2.0075 should be updated to version 9.2.0075 or later.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-78509
BDU:2026-02586
CVE-2026-28419
ECHO-E78F-34E3-BC82
GHSA-XCC8-R6C5-HVWV
MGASA-2026-0049
OESA-2026-1565
SUSE-SU-2026:0910-1
SUSE-SU-2026:1051-1
SUSE-SU-2026:1095-1
USN-8101-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim