Stack-based buffer overflow in Vim - CVE-2026-73070

 

Stack-based buffer overflow in Vim - CVE-2026-73070

Published: July 24, 2026 / Updated: August 13, 2026


Vulnerability identifier: #VU139258
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-73070
CWE-ID: CWE-121
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to stack-based buffer overflow in the Vim socket server backend when handling client connections. A local user can connect repeatedly to the server socket to cause a denial of service.

The issue affects Vim instances running as a server with the client-server socket backend enabled. No user interaction is required. On builds using the poll() path, about ten client connections are sufficient, while on builds using the select() path exploitation requires enough connections to exceed FD_SETSIZE and a limit on open files above 1024.


Affected software

Vim
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Desktop Applications Module
Basesystem Module
openSUSE Leap
vim-data
vim-debugsource
vim-debuginfo
gvim
gvim-debuginfo
vim
vim-data-common
vim-small-debuginfo
vim-small

How to mitigate CVE-2026-73070

Install security update from vendor's website.

Vim - update to 9.2.0842
vim-data - addressed in versions 9.2.0957-17.76.1, 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
vim-debugsource - addressed in versions 9.2.0957-17.76.1, 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
vim-debuginfo - addressed in versions 9.2.0957-17.76.1, 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
gvim - addressed in versions 9.2.0957-17.76.1, 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
gvim-debuginfo - addressed in versions 9.2.0957-17.76.1, 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
vim - addressed in versions 9.2.0957-17.76.1, 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
vim-data-common - addressed in versions 9.2.0957-17.76.1, 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
vim-small-debuginfo - addressed in versions 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1
vim-small - addressed in versions 9.2.0957-150000.5.102.1, 9.2.0957-150500.20.64.1

External References

Related Security Bulletins