Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.
CVSS Details
- CVSS 4.0 Base Score: 5.7 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade vim-minimalUpgrade vim-enhancedUpgrade vim-commonUpgrade vim-X11Upgrade vim-filesystem | Aug 2, 2026 | Jul 29, 2026 |
| Amazon Linux Ami 2 | — | Upgrade vim-debuginfoUpgrade vim-enhancedUpgrade vim-X11Upgrade vim-filesystemUpgrade vim-commonUpgrade vim-dataUpgrade xxdUpgrade vim-minimal | Jul 22, 2026 | Jul 22, 2026 |
| Amazon_linux_2023 | — | Upgrade vim-dataUpgrade vim-minimalUpgrade xxdUpgrade xxd-debuginfoUpgrade vim-minimal-debuginfoUpgrade vim-enhancedUpgrade vim-enhanced-debuginfoUpgrade vim-debugsourceUpgrade vim-filesystemUpgrade vim-commonUpgrade vim-debuginfoUpgrade vim-default-editor | Jul 21, 2026 | Jun 25, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | Jun 25, 2026 |
| Redhat_linux | — | Upgrade xxd-debuginfoUpgrade vim-minimalUpgrade xxdUpgrade vim-enhanced-debuginfoUpgrade vim-dataUpgrade vim-minimal-debuginfoUpgrade vim-filesystemUpgrade vim-debuginfoUpgrade vim-X11-debuginfoUpgrade vim-enhancedUpgrade vim-debugsourceUpgrade vim-commonUpgrade vim-common-debuginfoUpgrade vim-X11 | Jul 17, 2026 | Jun 25, 2026 |
| Rocky_linux | — | Upgrade vim-X11Upgrade vim-debuginfoUpgrade vim-minimal-debuginfoUpgrade vim-X11-debuginfoUpgrade vim-commonUpgrade vim-debugsourceUpgrade vim-common-debuginfoUpgrade vim-minimalUpgrade vim-enhancedUpgrade vim-enhanced-debuginfo | Aug 3, 2026 | Jul 31, 2026 |
| Ubuntu | — | Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-tinyUpgrade vimUpgrade vim-gtk3Upgrade vim-gtkUpgrade xxd (Ubuntu Pro)Upgrade vim-motifUpgrade xxdUpgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-gui-common (Ubuntu Pro)Upgrade vim-lesstif (Ubuntu Pro)Upgrade vim-nox (Ubuntu Pro)Upgrade vim-runtime (Ubuntu Pro)Upgrade vim-gtk (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-athena (Ubuntu Pro)Upgrade vim-noxUpgrade vim-athenaUpgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-commonUpgrade vim-tiny (Ubuntu Pro)Upgrade vim-runtimeUpgrade vim (Ubuntu Pro) | Jul 5, 2026 | Jul 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 6, 2026 | Jun 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub