Aller au contenu

Fiche vulnérabilité

CVE-2026-57454 : faille moyenne vim vim (CVSS 6.1)

Description

Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose offset and length point outside the line's property data. When Vim restores or displays such a line it converts the offset into a pointer and reads the virtual text without bounds checking, causing an out-of-bounds read that can crash Vim or disclose adjacent heap memory. This vulnerability is fixed in 9.2.0679.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
25 juin 2026
Dernière mise à jour
26 juin 2026

Produits concernés

  • vim vim

Références

Rechercher une autre vulnérabilité dans la base CVE