Back

LOW

Vim: Use-after-free in JSON Decoding

Published Aug 11, 2026

Description

Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.

Affected products

Remediation

Red Hat statement

Red Hat's shipped vim versions across all supported RHEL releases (6 through 10), RHIVOS, and RHCOS are outside the vulnerable range introduced in upstream vim 9.2.0511 and fixed in 9.2.0844 -- RHEL/RHIVOS ship the 7.x, 8.x, or 9.1.x branch depending on release, all of which predate the introduction of this flaw. Fedora and Hummingbird already ship 9.2.920, which is past the fix. No Red Hat product is affected by this vulnerability.

Red Hat mitigation

Not applicable -- no Red Hat product ships a vim version within the vulnerable range.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 10, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Awaiting Analysis
Modified Sep 9, 2026
Red Hat
Severity Low
Public date Aug 11, 2026