CVE-2026-28418

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary. Version 9.2.0074 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:28

Type Values Removed Values Added
Summary
  • (es) Vim es un editor de texto de código abierto y de línea de comandos. Antes de la versión 9.2.0074, hay un desbordamiento de búfer basado en montículo con lectura fuera de límites en la lógica de análisis de archivos de etiquetas estilo Emacs de Vim. Al procesar un archivo de etiquetas malformado, Vim puede ser engañado para leer hasta 7 bytes más allá del límite de memoria asignada. La versión 9.2.0074 corrige el problema.

03 Mar 2026, 17:49

Type Values Removed Values Added
References () https://github.com/vim/vim/commit/f6a7f469a9c0d09e84cd6cb - () https://github.com/vim/vim/commit/f6a7f469a9c0d09e84cd6cb - Patch
References () https://github.com/vim/vim/releases/tag/v9.2.0074 - () https://github.com/vim/vim/releases/tag/v9.2.0074 - Release Notes
References () https://github.com/vim/vim/security/advisories/GHSA-h4mf-vg97-hj8j - () https://github.com/vim/vim/security/advisories/GHSA-h4mf-vg97-hj8j - Patch, Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2026/02/27/7 - () http://www.openwall.com/lists/oss-security/2026/02/27/7 - Mailing List, Patch, Third Party Advisory
First Time Vim vim
Vim
CPE cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*

28 Feb 2026, 01:16

Type Values Removed Values Added
References
  • () http://www.openwall.com/lists/oss-security/2026/02/27/7 -

27 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 22:16

Updated : 2026-06-17 10:28


NVD link : CVE-2026-28418

Mitre link : CVE-2026-28418

CVE.ORG link : CVE-2026-28418


JSON object : View

Products Affected

vim

  • vim
CWE
CWE-122

Heap-based Buffer Overflow

CWE-125

Out-of-bounds Read