Back

HIGH

Vim: Heap Buffer Overflow in Text Property Handling

Published Aug 11, 2026

Description

Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue is fixed in version 9.2.0841.

Affected products

Remediation

Red Hat statement

This Moderate impact vulnerability in Vim's text property handling can lead to a heap buffer overflow. Exploitation requires a local attacker to provide specially crafted input, such as a malicious file or Vim script, that causes an integer wraparound. This scenario is not expected during normal use of the editor.

Red Hat mitigation

Do not run untrusted Vim scripts or plugins that call prop_add() in an unbounded loop on one line. Opening a file is not enough unless a loaded plugin attaches tens of thousands of text properties from that input

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 12, 2026
Reserved Aug 10, 2026

CISA Vulnrichment

Updated Aug 12, 2026

NVD

Status Analyzed
Modified Oct 6, 2026

Red Hat

Severity Moderate
Public date Aug 11, 2026
Bugzilla 2514035

ENISA EUVD

Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 12, 2026

GitHub

No data