Количество 14
Количество 14
CVE-2026-57455
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698.
CVE-2026-57455
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698.
CVE-2026-57455
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698.
CVE-2026-57455
Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument
CVE-2026-57455
Vim is an open source, command line text editor. Prior to 9.2.0698, th ...
ROS-20260819-80-0032
Уязвимость vim
ROS-20260819-73-0032
Уязвимость vim
BDU:2026-14499
Уязвимость функций spell_soundfold_sofo() файла src/spell.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
RLSA-2026:48703
Important: vim security update
ELSA-2026-48703
ELSA-2026-48703: vim security update (IMPORTANT)
RLSA-2026:48650
Important: vim security update
RLSA-2026:47982
Important: vim security update
ELSA-2026-48650
ELSA-2026-48650: vim security update (IMPORTANT)
ELSA-2026-47982
ELSA-2026-47982: vim security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57455 Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57455 Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698. | CVSS3: 4.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-57455 Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57455 Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57455 Vim is an open source, command line text editor. Prior to 9.2.0698, th ... | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
ROS-20260819-80-0032 Уязвимость vim | CVSS3: 7 | 0% Низкий | 30 дней назад | |
ROS-20260819-73-0032 Уязвимость vim | CVSS3: 7 | 0% Низкий | 30 дней назад | |
BDU:2026-14499 Уязвимость функций spell_soundfold_sofo() файла src/spell.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
RLSA-2026:48703 Important: vim security update | около 2 месяцев назад | |||
ELSA-2026-48703 ELSA-2026-48703: vim security update (IMPORTANT) | около 2 месяцев назад | |||
RLSA-2026:48650 Important: vim security update | около 2 месяцев назад | |||
RLSA-2026:47982 Important: vim security update | около 2 месяцев назад | |||
ELSA-2026-48650 ELSA-2026-48650: vim security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-47982 ELSA-2026-47982: vim security update (IMPORTANT) | около 2 месяцев назад |
Уязвимостей на страницу