Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73075

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.

A flaw was found in Vim, an open-source text editor. This vulnerability involves an out-of-bounds memory access within the popup opacity handling feature. A local attacker could exploit this by using specially crafted Vim script, leading to an out-of-bounds read and a limited out-of-bounds write. While the editor is expected to continue functioning, this could potentially result in unexpected behavior or information disclosure.

Отчет

Moderate: This flaw in Vim involves an out-of-bounds memory access during popup opacity handling. Exploitation requires a local attacker to execute specially crafted Vim script that utilizes specific popup window features, making user interaction a prerequisite. The impact is typically limited to an out-of-bounds read and a constrained write, which may lead to unexpected behavior but is not expected to result in immediate system compromise or arbitrary code execution. None of the Red Hat products ship this vulnerable code. Hence, are not affected.

Меры по смягчению последствий

To mitigate this issue, users should avoid running untrusted Vim scripts or installing untrusted plugins. This vulnerability is triggered by the execution of malicious Vim script code, not merely by opening a file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimNot affected
Red Hat Enterprise Linux 6vimNot affected
Red Hat Enterprise Linux 7vimNot affected
Red Hat Enterprise Linux 8vimNot affected
Red Hat Enterprise Linux 9vimNot affected
Red Hat Hardened ImagesvimNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2514039vim: Vim: Out-of-bounds Access in Popup Opacity Handling

EPSS

Процентиль: 2%
0.00117
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

ubuntu
17 дней назад

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.

nvd
17 дней назад

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.

msrc
6 дней назад

Vim: Out-of-bounds Access in Popup Opacity Handling

debian
17 дней назад

Vim is an open source, command line text editor. From 9.2.0469 until 9 ...

EPSS

Процентиль: 2%
0.00117
Низкий

4.4 Medium

CVSS3