Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:47982

Опубликовано: 30 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: vim security update

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

  • vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455)

  • vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456)

  • vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693)

  • vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion (CVE-2026-59856)

  • vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
vim-filesystemnoarch26.el9_8.13vim-filesystem-8.2.2637-26.el9_8.13.noarch.rpm
vim-minimalaarch6426.el9_8.13vim-minimal-8.2.2637-26.el9_8.13.aarch64.rpm
vim-minimalx86_6426.el9_8.13vim-minimal-8.2.2637-26.el9_8.13.x86_64.rpm

Показывать по

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.3
redhat
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.8
nvd
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.8
msrc
около 1 месяца назад

Vim: Out-of-bounds Write in Spell File Word Count

CVSS3: 7.8
debian
около 1 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, th ...