Stack-based buffer overflow in Vim - #VU139258
Published: July 24, 2026 / Updated: July 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in the Vim socket server backend when handling client connections. A local user can connect repeatedly to the server socket to cause a denial of service.
The issue affects Vim instances running as a server with the client-server socket backend enabled. No user interaction is required. On builds using the poll() path, about ten client connections are sufficient, while on builds using the select() path exploitation requires enough connections to exceed FD_SETSIZE and a limit on open files above 1024.