Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits the composing bytes of that character as separate NFA states. This corrupts the NFA postfix stack, resulting in NFA_START_COLL having a NULL out1 pointer. When nfa_max_width() subsequently traverses the compiled NFA to estimate match width for the look-behind assertion, it dereferences state->out1->out without a NULL check, causing a segmentation fault. This vulnerability is fixed in 9.2.0137.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | Mar 13, 2026 | Mar 12, 2026 |
| Amazon_linux_2023 | — | Upgrade vim-filesystemUpgrade vim-debuginfoUpgrade vim-minimal-debuginfoUpgrade vim-commonUpgrade vim-default-editorUpgrade vim-enhancedUpgrade vim-enhanced-debuginfoUpgrade vim-debugsourceUpgrade vim-minimalUpgrade xxdUpgrade vim-dataUpgrade xxd-debuginfo | Apr 14, 2026 | Mar 12, 2026 |
| Ubuntu | — | Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vim-athenaUpgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-gui-common (Ubuntu Pro)Upgrade vim-commonUpgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-gtk (Ubuntu Pro)Upgrade vim-tiny (Ubuntu Pro)Upgrade vim-noxUpgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-tinyUpgrade vim-gtkUpgrade vim (Ubuntu Pro)Upgrade vim-motifUpgrade vim-lesstif (Ubuntu Pro)Upgrade xxd (Ubuntu Pro)Upgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-athena (Ubuntu Pro)Upgrade vim-runtime (Ubuntu Pro)Upgrade xxdUpgrade vim-gtk3Upgrade vimUpgrade vim-runtime | Apr 15, 2026 | Apr 13, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Mar 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub