Out-of-bounds read in Vim - CVE-2026-57454
Published: June 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in text property handling when processing a crafted undo or swap file. A remote attacker can trick the victim into opening a crafted undo or swap file to disclose sensitive information or cause a denial of service.
User interaction is required to open a crafted undo or swap file.