Junglewise Threat Intelligence

CVE-2026-52859: Vim out-of-bounds read in update_snapshot function

CVE-2026-52859 · Severity: info · CVSS 6.9 · Published 2026-06-11

Technologies: Vim. Vendors: Vim.

Executive brief

Vim is a widely used open-source text editor. A vulnerability in its terminal emulator component allows a malicious program or script running inside a Vim terminal window to crash the editor. This could lead to a loss of unsaved work or a disruption of operations for users who rely on Vim's built-in terminal features.

Technical details

An out-of-bounds read vulnerability exists in Vim's `update_snapshot()` function within `src/terminal.c`. The function iterates through a cell's `chars[]` array without an upper bound, relying solely on a NUL terminator. When a terminal cell is filled with the maximum allowed characters (one base character and five combining marks), the underlying `libvterm` library returns the array without a NUL terminator. This causes the loop to read past the six-element array and append out-of-bounds data to a fixed-size buffer. An attacker can trigger this by running a program inside a `:terminal` window that outputs a specific byte sequence, resulting in an application crash (DoS). The vulnerability is fixed in version 9.2.0565 by adding a loop guard.

Affected products

  • Vim Vim < 9.2.0565

Timeline

  • 2026-05-30: patched: Patch 9.2.0565 released
  • 2026-05-30: advisory: GitHub Security Advisory published
  • 2026-06-11: disclosed: CVE published to NVD

References

Related threats