Vim: Heap Buffer Overflow in Text Property Handling
Published Aug 11, 2026
7.1
HIGHCVSS 4.0
EPSS 0.10%
Description
Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue is fixed in version 9.2.0841.
Affected products
-
Affected
- < 9.2.0841
No data.
Red Hat Enterprise Linux 10
vim
Not affected
Red Hat Enterprise Linux 6
vim
Not affected
Red Hat Enterprise Linux 7
vim
Not affected
Red Hat Enterprise Linux 8
vim
Not affected
Red Hat Enterprise Linux 9
vim
Not affected
Red Hat Hardened Images
vim
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 6 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 7 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | vim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | vim | Not affected | n/a |
| Red Hat Hardened Images | vim | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact vulnerability in Vim's text property handling can lead to a heap buffer overflow. Exploitation requires a local attacker to provide specially crafted input, such as a malicious file or Vim script, that causes an integer wraparound. This scenario is not expected during normal use of the editor.
Red Hat mitigation
Do not run untrusted Vim scripts or plugins that call prop_add() in an unbounded loop on one line. Opening a file is not enough unless a loaded plugin attaches tens of thousands of text properties from that input
References (7)
- https://access.redhat.com/security/cve/CVE-2026-73074 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2514035 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-56229 Advisory
- https://github.com/vim/vim/commit/a9336b476fd1a182e3f79b5f83c0ffb04f8a922b x_refsource_MISC
- https://github.com/vim/vim/security/advisories/GHSA-hm4g-pjfx-m27j x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-73074
- https://www.cve.org/CVERecord?id=CVE-2026-73074
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data