Back

HIGH

Vim: Heap Buffer Overflow when Loading a Spell File

Published Aug 11, 2026

Description

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.

Affected products

Remediation

Red Hat statement

A local attacker can exploit an Important heap buffer overflow in Vim to execute arbitrary code by tricking a user into loading a malicious spell file.

Red Hat mitigation

If spell checking is unused, disable it with set nospell in ~/.vimrc and do not set spelllang. If spell is required, load only trusted .spl files from Vim’s spell directories and do not place untrusted spell files on runtimepath. Additionally, consider disabling modelines (set nomodeline in ~/.vimrc) to prevent untrusted text files from automatically overriding these settings when opened.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Sep 17, 2026
Reserved Aug 10, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Analyzed
Modified Oct 6, 2026
Red Hat
Severity Important
Public date Aug 11, 2026
ENISA EUVD
Assigner GitHub_M
Published Aug 11, 2026
Updated Sep 17, 2026
Exploited since n/a
EUVD-2026-56226