Vim: Use-after-free in JSON Decoding
Published Aug 11, 2026
3.3
LOWCVSS 3.1
EPSS 0.16%
Description
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
Affected products
-
- Version >= 9.2.0511, < 9.2.0844StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Enterprise Linux 10
vim
Not affected
Red Hat Enterprise Linux 6
vim
Not affected
Red Hat Enterprise Linux 7
vim
Not affected
Red Hat Enterprise Linux 8
vim
Not affected
Red Hat Enterprise Linux 9
vim
Not affected
Red Hat Hardened Images
vim
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 6 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 7 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | vim | Not affected | n/a |
| Red Hat Hardened Images | vim | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat's shipped vim versions across all supported RHEL releases (6 through 10), RHIVOS, and RHCOS are outside the vulnerable range introduced in upstream vim 9.2.0511 and fixed in 9.2.0844 -- RHEL/RHIVOS ship the 7.x, 8.x, or 9.1.x branch depending on release, all of which predate the introduction of this flaw. Fedora and Hummingbird already ship 9.2.920, which is past the fix. No Red Hat product is affected by this vulnerability.
Red Hat mitigation
Not applicable -- no Red Hat product ships a vim version within the vulnerable range.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 11, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.16% (0.00156) | 4.10th | v5 (v2026.06.15) |
| Aug 12, 2026 | 0.11% (0.00109) | 1.44th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-73071 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2514036 Issue Tracking
- https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75 x_refsource_MISC
- https://github.com/vim/vim/releases/tag/v9.2.0844 x_refsource_MISC
- https://github.com/vim/vim/security/advisories/GHSA-69ch-22ch-r887 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-73071
- https://www.cve.org/CVERecord?id=CVE-2026-73071
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-73071 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2514036 | Issue Tracking | |
| https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75 | x_refsource_MISC | |
| https://github.com/vim/vim/releases/tag/v9.2.0844 | x_refsource_MISC | |
| https://github.com/vim/vim/security/advisories/GHSA-69ch-22ch-r887 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-73071 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-73071 |
Change history (0)
No recorded changes yet.