https://seclists.org/oss-sec/2026/q1/235: [vim-security] Heap-based Buffer Underflow in Emacs tags parsing affects Vim < 9.2.0075
Published Feb 27, 2026
·Updated
Affected Software
1 affected component
vim<9.2.0075
Frequently Asked Questions
1
What is the severity of CVE-2026-28419?
CVE-2026-28419 has a medium severity rating.
2
How do I fix CVE-2026-28419?
To fix CVE-2026-28419, update Vim to version 9.2.0075 or later.
3
What vulnerability does CVE-2026-28419 describe?
CVE-2026-28419 describes a heap-based buffer underflow in Emacs tags parsing affecting Vim versions below 9.2.0075.
4
What potential impact does CVE-2026-28419 have?
CVE-2026-28419 may lead to out-of-bounds reads, which can compromise application integrity.
5
Which versions of Vim are affected by CVE-2026-28419?
Versions of Vim prior to 9.2.0075 are affected by CVE-2026-28419.