Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698.
CVSS Details
- CVSS 4.0 Base Score: 4 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade vim-enhancedUpgrade vim-X11Upgrade vim-filesystemUpgrade vim-minimalUpgrade vim-common | Aug 2, 2026 | Jul 29, 2026 |
| Alpine Linux | — | Upgrade vim | Jun 26, 2026 | Jun 25, 2026 |
| Amazon_linux_2023 | — | Upgrade vim-enhancedUpgrade vim-minimal-debuginfoUpgrade vim-debuginfoUpgrade vim-debugsourceUpgrade xxdUpgrade vim-default-editorUpgrade vim-filesystemUpgrade vim-minimalUpgrade vim-commonUpgrade vim-dataUpgrade vim-enhanced-debuginfoUpgrade xxd-debuginfo | Jul 21, 2026 | Jun 25, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | Jun 25, 2026 |
| Redhat_linux | — | Upgrade vim-dataUpgrade xxd-debuginfoUpgrade vim-debuginfoUpgrade vim-X11Upgrade vim-filesystemUpgrade vim-minimal-debuginfoUpgrade xxdUpgrade vim-enhancedUpgrade vim-enhanced-debuginfoUpgrade vim-minimalUpgrade vim-debugsourceUpgrade vim-common-debuginfoUpgrade vim-X11-debuginfoUpgrade vim-common | Jul 17, 2026 | Jun 25, 2026 |
| Rocky_linux | — | Upgrade vim-minimal-debuginfoUpgrade vim-minimalUpgrade vim-X11Upgrade vim-common-debuginfoUpgrade vim-enhancedUpgrade vim-X11-debuginfoUpgrade vim-debugsourceUpgrade vim-debuginfoUpgrade vim-commonUpgrade vim-enhanced-debuginfo | Aug 3, 2026 | Jul 31, 2026 |
| Ubuntu | — | Upgrade vim-athena (Ubuntu Pro)Upgrade vim-tiny (Ubuntu Pro)Upgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-commonUpgrade vim-athenaUpgrade vim-gui-commonUpgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-noxUpgrade vim-gtk (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-runtimeUpgrade vim-gui-common (Ubuntu Pro)Upgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-runtime (Ubuntu Pro)Upgrade vim (Ubuntu Pro)Upgrade xxd (Ubuntu Pro)Upgrade vim-gtkUpgrade vimUpgrade vim-lesstif (Ubuntu Pro)Upgrade vim-gtk3Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-tinyUpgrade vim-nox-py2 (Ubuntu Pro)Upgrade xxdUpgrade vim-motif | Jul 5, 2026 | Jul 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 13, 2026 | Jun 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub