Количество 14
Количество 14
BDU:2026-14508
Уязвимость функции dump_prefixes() файла src/spell.c текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2026-55892
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.
CVE-2026-55892
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.
CVE-2026-55892
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.
CVE-2026-55892
Vim: Out-of-bounds Write in Spell File Prefix Dump
CVE-2026-55892
Vim is an open source, command line text editor. Prior to 9.2.0662, th ...
ROS-20260819-80-0028
Уязвимость vim
ROS-20260819-73-0028
Уязвимость vim
RLSA-2026:66348
Important: vim security update
ELSA-2026-66348-0
ELSA-2026-66348-0: vim security update (IMPORTANT)
RLSA-2026:66366
Important: vim security update
RLSA-2026:66336
Important: vim security update
ELSA-2026-66366-0
ELSA-2026-66366-0: vim security update (IMPORTANT)
ELSA-2026-66336-0
ELSA-2026-66336-0: vim security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-14508 Уязвимость функции dump_prefixes() файла src/spell.c текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55892 Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55892 Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55892 Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55892 Vim: Out-of-bounds Write in Spell File Prefix Dump | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-55892 Vim is an open source, command line text editor. Prior to 9.2.0662, th ... | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
ROS-20260819-80-0028 Уязвимость vim | CVSS3: 5.5 | 0% Низкий | 30 дней назад | |
ROS-20260819-73-0028 Уязвимость vim | CVSS3: 5.5 | 0% Низкий | 30 дней назад | |
RLSA-2026:66348 Important: vim security update | 7 дней назад | |||
ELSA-2026-66348-0 ELSA-2026-66348-0: vim security update (IMPORTANT) | 8 дней назад | |||
RLSA-2026:66366 Important: vim security update | 6 дней назад | |||
RLSA-2026:66336 Important: vim security update | 6 дней назад | |||
ELSA-2026-66366-0 ELSA-2026-66366-0: vim security update (IMPORTANT) | 8 дней назад | |||
ELSA-2026-66336-0 ELSA-2026-66336-0: vim security update (IMPORTANT) | 8 дней назад |
Уязвимостей на страницу