Vim: Out-of-bounds Write in Spell File Word Count
Published Jun 25, 2026
5.7
MEDIUMCVSS 4.0
EPSS 0.12%
Description
Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.
Affected products
-
- Version < 9.2.0653StatusaffectedConstraints-
- Version
No data.
Red Hat Enterprise Linux 10
vim-2:9.1.083-9.el10_2.12
Fixed · RHSA-2026:48650
Red Hat Enterprise Linux 10.0 Extended Update Support
vim-2:9.1.083-5.el10_0.4
Fixed · RHSA-2026:55431
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
vim-2:7.4.629-5.el6_10.4
Fixed · RHSA-2026:69128
Red Hat Enterprise Linux 7 Extended Lifecycle Support
vim-2:7.4.629-8.el7_9.2
Fixed · RHSA-2026:68711
Red Hat Enterprise Linux 8
vim-2:8.0.1763-31.el8_10
Fixed · RHSA-2026:48703
Red Hat Enterprise Linux 8
vim-2:8.0.1763-31.el8_10
Fixed · RHSA-2026:48703
Red Hat Enterprise Linux 9
vim-2:8.2.2637-26.el9_8.13
Fixed · RHSA-2026:47982
Red Hat Enterprise Linux 9
vim-2:8.2.2637-26.el9_8.13
Fixed · RHSA-2026:47982
Red Hat Hardened Images
vim-main-9.2.725-1.hum1
Fixed · RHSA-2026:30267
Red Hat Insights proxy 1.5
insights-proxy/insights-proxy-container-rhel9:1786433656
Fixed · RHSA-2026:53371
Red Hat OpenShift Container Platform 4.22
rhcos-4.22.9.8.202608130832-0
Fixed · RHSA-2026:54769
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-rhel9:1786435241
Fixed · RHSA-2026:54387
Red Hat Update Infrastructure 5
rhui5/cds-kubernetes-tp-rhel9:1787241211
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/cds-rhel9:1786533457
Fixed · RHSA-2026:54387
Red Hat Update Infrastructure 5
rhui5/haproxy-rhel9:1786533449
Fixed · RHSA-2026:54387
Red Hat Update Infrastructure 5
rhui5/installer-rhel9:1786435483
Fixed · RHSA-2026:54387
Red Hat Update Infrastructure 5
rhui5/installer-tp-rhel9:1787135742
Fixed · RHSA-2026:58981
Red Hat Update Infrastructure 5
rhui5/rhua-rhel9:1786533529
Fixed · RHSA-2026:54387
Red Hat Update Infrastructure 5
rhui5/rhua-tp-rhel9:1787241260
Fixed · RHSA-2026:58981
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | vim-2:9.1.083-9.el10_2.12 | Fixed | RHSA-2026:48650 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | vim-2:9.1.083-5.el10_0.4 | Fixed | RHSA-2026:55431 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | vim-2:7.4.629-5.el6_10.4 | Fixed | RHSA-2026:69128 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | vim-2:7.4.629-8.el7_9.2 | Fixed | RHSA-2026:68711 |
| Red Hat Enterprise Linux 8 | vim-2:8.0.1763-31.el8_10 | Fixed | RHSA-2026:48703 |
| Red Hat Enterprise Linux 8 | vim-2:8.0.1763-31.el8_10 | Fixed | RHSA-2026:48703 |
| Red Hat Enterprise Linux 9 | vim-2:8.2.2637-26.el9_8.13 | Fixed | RHSA-2026:47982 |
| Red Hat Enterprise Linux 9 | vim-2:8.2.2637-26.el9_8.13 | Fixed | RHSA-2026:47982 |
| Red Hat Hardened Images | vim-main-9.2.725-1.hum1 | Fixed | RHSA-2026:30267 |
| Red Hat Insights proxy 1.5 | insights-proxy/insights-proxy-container-rhel9:1786433656 | Fixed | RHSA-2026:53371 |
| Red Hat OpenShift Container Platform 4.22 | rhcos-4.22.9.8.202608130832-0 | Fixed | RHSA-2026:54769 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-rhel9:1786435241 | Fixed | RHSA-2026:54387 |
| Red Hat Update Infrastructure 5 | rhui5/cds-kubernetes-tp-rhel9:1787241211 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/cds-rhel9:1786533457 | Fixed | RHSA-2026:54387 |
| Red Hat Update Infrastructure 5 | rhui5/haproxy-rhel9:1786533449 | Fixed | RHSA-2026:54387 |
| Red Hat Update Infrastructure 5 | rhui5/installer-rhel9:1786435483 | Fixed | RHSA-2026:54387 |
| Red Hat Update Infrastructure 5 | rhui5/installer-tp-rhel9:1787135742 | Fixed | RHSA-2026:58981 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-rhel9:1786533529 | Fixed | RHSA-2026:54387 |
| Red Hat Update Infrastructure 5 | rhui5/rhua-tp-rhel9:1787241260 | Fixed | RHSA-2026:58981 |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact vulnerability in Vim's spell suggestion feature allows an attacker to cause a denial of service. By tricking a user into loading a specially crafted spell file and invoking spell suggestion, an out-of-bounds write can occur, leading to a crash of the editor. This requires user interaction and a malicious file, limiting its immediate exploitability.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
1 other source (NVD) ▾
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jun 26, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Jun–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.12% (0.00124) | 1.87th | v5 (v2026.06.15) |
| Jun 26, 2026 | 0.13% (0.00126) | 2.63th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-55693 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492980 Issue Tracking
- https://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7 x_refsource_MISCPatch
- https://github.com/vim/vim/releases/tag/v9.2.0653 x_refsource_MISCProduct
- https://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-55693
- https://www.cve.org/CVERecord?id=CVE-2026-55693
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-55693 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2492980 | Issue Tracking | |
| https://github.com/vim/vim/commit/a80874d9b84a01040e3d1aef2d4a59e1934dafb7 | x_refsource_MISCPatch | |
| https://github.com/vim/vim/releases/tag/v9.2.0653 | x_refsource_MISCProduct | |
| https://github.com/vim/vim/security/advisories/GHSA-wgh4-64f7-q3jq | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-55693 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-55693 |
Change history (0)
No recorded changes yet.