Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.
CVSS Details
- CVSS 4.0 Base Score: 5.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade vim | Jul 14, 2026 | Jul 9, 2026 |
| Amazon_linux_2023 | — | Upgrade vim-default-editorUpgrade vim-enhancedUpgrade vim-filesystemUpgrade vim-enhanced-debuginfoUpgrade xxdUpgrade vim-dataUpgrade vim-minimal-debuginfoUpgrade vim-debugsourceUpgrade xxd-debuginfoUpgrade vim-minimalUpgrade vim-commonUpgrade vim-debuginfo | Aug 10, 2026 | Jul 9, 2026 |
| Redhat_linux | — | Upgrade vim-enhancedUpgrade vim-minimalUpgrade vim-debugsourceUpgrade vim-debuginfoUpgrade vim-filesystemUpgrade vim-common-debuginfoUpgrade vim-dataUpgrade vim-commonNo solution existsUpgrade xxd-debuginfoUpgrade vim-enhanced-debuginfoUpgrade xxdUpgrade vim-X11-debuginfoUpgrade vim-minimal-debuginfoUpgrade vim-X11 | Jul 17, 2026 | Jul 9, 2026 |
| Rocky_linux | — | Upgrade vim-commonUpgrade vim-enhanced-debuginfoUpgrade xxd-debuginfoUpgrade vim-debuginfoUpgrade vim-minimalUpgrade vim-common-debuginfoUpgrade vim-X11-debuginfoUpgrade vim-minimal-debuginfoUpgrade vim-debugsourceUpgrade vim-X11Upgrade vim-enhancedUpgrade xxd | Sep 15, 2026 | Sep 11, 2026 |
| Ubuntu | — | Upgrade vim-gtk3Upgrade vim-gui-common (Ubuntu Pro)Upgrade vimUpgrade xxd (Ubuntu Pro)Upgrade vim-motifUpgrade vim-gnome (Ubuntu Pro)Upgrade vim-athena-py2 (Ubuntu Pro)Upgrade vim-runtime (Ubuntu Pro)Upgrade vim-gui-commonUpgrade vim-nox (Ubuntu Pro)Upgrade vim-nox-py2 (Ubuntu Pro)Upgrade vim-athena (Ubuntu Pro)Upgrade vim-commonUpgrade vim-lesstif (Ubuntu Pro)Upgrade vim-gtk3 (Ubuntu Pro)Upgrade vim-tinyUpgrade xxdUpgrade vim-gtk3-py2 (Ubuntu Pro)Upgrade vim-common (Ubuntu Pro)Upgrade vim-gnome-py2 (Ubuntu Pro)Upgrade vim-noxUpgrade vim-athenaUpgrade vim (Ubuntu Pro)Upgrade vim-gtk (Ubuntu Pro)Upgrade vim-tiny (Ubuntu Pro)Upgrade vim-gtkUpgrade vim-gtk-py2 (Ubuntu Pro)Upgrade vim-runtime | Jul 15, 2026 | Jul 14, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 13, 2026 | Jul 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub