Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (xchacha20poly1305, requires the +sodium feature) whose body is shorter than a single libsodium secretstream header, an unsigned length calculation underflows and a subsequent decryption call reads far past the end of the input buffer, crashing Vim. This vulnerability is fixed in 9.2.0671.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | Jun 26, 2026 | Jun 25, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 25, 2026 |
| Ubuntu | — | Upgrade vim-nox (Ubuntu Pro)Upgrade vim-gnome (Ubuntu Pro)Upgrade vim-commonUpgrade vim-lesstif (Ubuntu Pro)Upgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-athena (Ubuntu Pro)Upgrade vim-runtimeUpgrade vim-runtime (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-athenaUpgrade vim-gui-common (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim (Ubuntu Pro)Upgrade vim-gtk (Ubuntu Pro)Upgrade vim-noxUpgrade vim-motifUpgrade vim-tiny (Ubuntu Pro)Upgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-gtk-py2 (Ubuntu Pro)Upgrade xxdUpgrade vim-gtkUpgrade vim-tinyUpgrade vim-gtk3Upgrade vimUpgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade xxd (Ubuntu Pro) | Jul 5, 2026 | Jul 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 13, 2026 | Jun 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub