Out-of-bounds read in Vim - #VU132276
Published: May 25, 2026
Vim
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in tree_count_words() when parsing a crafted spell file. A remote attacker can supply a crafted .spl file to trigger a one-byte heap out-of-bounds read to cause a denial of service.
The issue is triggered during .sug file loading on a tree whose final sibling is BY_NOFLAGS.