Stack-based buffer overflow in Vim - #VU139258

 

Stack-based buffer overflow in Vim - #VU139258

Published: July 24, 2026 / Updated: July 24, 2026


Vulnerability identifier: #VU139258
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to stack-based buffer overflow in the Vim socket server backend when handling client connections. A local user can connect repeatedly to the server socket to cause a denial of service.

The issue affects Vim instances running as a server with the client-server socket backend enabled. No user interaction is required. On builds using the poll() path, about ten client connections are sufficient, while on builds using the select() path exploitation requires enough connections to exceed FD_SETSIZE and a limit on open files above 1024.


Affected software

Vim

Remediation

Install security update from vendor's website.

Vim - update to 9.2.0842

External References

Related Security Bulletins