Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-52859

Опубликовано: 11 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.2

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus five combining marks — the bundled libvterm returns the array without a terminating NUL, so the loop reads past the fixed six-element array and appends the out-of-bounds values to a buffer reserved for only six characters. A program whose output is rendered inside a :terminal window can trigger this with a short byte sequence and no Vim scripting, leading to a crash. This issue has been patched in version 9.2.0565.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

released

2:8.0.1453-1ubuntu1.13+esm20
esm-infra/focal

released

2:8.1.2269-1ubuntu5.32+esm8
jammy

released

2:8.2.3995-1ubuntu2.32
noble

released

2:9.1.0016-1ubuntu7.16
questing

released

2:9.1.0967-1ubuntu6.7
resolute

released

2:9.1.2141-1ubuntu4.5
upstream

not-affected

9.2.565

Показывать по

EPSS

Процентиль: 22%
0.00303
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 5
redhat
около 2 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus five combining marks — the bundled libvterm returns the array without a terminating NUL, so the loop reads past the fixed six-element array and appends the out-of-bounds values to a buffer reserved for only six characters. A program whose output is rendered inside a :terminal window can trigger this with a short byte sequence and no Vim scripting, leading to a crash. This issue has been patched in version 9.2.0565.

CVSS3: 8.2
nvd
около 2 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus five combining marks — the bundled libvterm returns the array without a terminating NUL, so the loop reads past the fixed six-element array and appends the out-of-bounds values to a buffer reserved for only six characters. A program whose output is rendered inside a :terminal window can trigger this with a short byte sequence and no Vim scripting, leading to a crash. This issue has been patched in version 9.2.0565.

msrc
около 2 месяцев назад

Vim: Out-of-bounds Read in Terminal Screen Snapshot

CVSS3: 8.2
debian
около 2 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

EPSS

Процентиль: 22%
0.00303
Низкий

8.2 High

CVSS3