PT-2026-22418 · Vim+3 · Vim+3

Ehdgks0627

·

Published

2026-02-27

·

Updated

2026-05-24

·

CVE-2026-28419

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0075
Description Vim, an open source command line text editor, contains a heap-based buffer underflow issue in its Emacs-style tags file parsing logic. When processing a malformed tags file containing a delimiter at the start of a line, Vim attempts to read memory before the allocated buffer. This can potentially lead to a denial-of-service condition.
Recommendations Versions prior to 9.2.0075 should be updated to version 9.2.0075 or later.

Exploit

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

AZL-78509
BDU:2026-02586
CVE-2026-28419
ECHO-E78F-34E3-BC82
GHSA-XCC8-R6C5-HVWV
MGASA-2026-0049
OESA-2026-1565
SUSE-SU-2026:0910-1
SUSE-SU-2026:1051-1
SUSE-SU-2026:1095-1
USN-8101-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim