PT-2026-22419 · Vim+3 · Vim+3

Ehdgks0627

·

Published

2026-02-27

·

Updated

2026-05-24

·

CVE-2026-28420

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Vim versions prior to 9.2.0076
Description Vim is an open source, command line text editor. A heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. The issue relates to reading beyond the boundaries of a memory buffer. The :terminal component is affected.
Recommendations Versions prior to 9.2.0076 should be updated to version 9.2.0076.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Out of bounds Read

Weakness Enumeration

Related Identifiers

AZL-78503
BDU:2026-02588
CVE-2026-28420
ECHO-E482-E357-798E
GHSA-RVJ2-JRF9-2PHG
MGASA-2026-0049
OESA-2026-1565
SUSE-SU-2026:0910-1
SUSE-SU-2026:1051-1
SUSE-SU-2026:1095-1
USN-8101-1

Affected Products

Linuxmint
Red Os
Ubuntu
Vim