CVE-2026-28421: Vim has a heap-buffer-overflow and a segmentation fault
Vim has a heap-buffer-overflow and a segmentation fault
Other sources
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.2.0077
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28421?
CVE-2026-28421 is classified as critical due to its heap-buffer-overflow and potential for remote code execution.
How do I fix CVE-2026-28421?
To fix CVE-2026-28421, update Vim to version 9.2.0077 or later.
What versions are affected by CVE-2026-28421?
CVE-2026-28421 affects all versions of Vim prior to 9.2.0077.
What type of vulnerability is CVE-2026-28421?
CVE-2026-28421 is a heap-buffer-overflow vulnerability that can lead to a segmentation fault in Vim.
What could happen if CVE-2026-28421 is exploited?
Exploitation of CVE-2026-28421 could allow an attacker to execute arbitrary code on a system running the affected versions of Vim.