Executive brief
Vim is a widely used open-source text editor. A vulnerability in its terminal emulator component allows a malicious program or script running inside a Vim terminal window to crash the editor. This could lead to a loss of unsaved work or a disruption of operations for users who rely on Vim's built-in terminal features.
Technical details
An out-of-bounds read vulnerability exists in Vim's `update_snapshot()` function within `src/terminal.c`. The function iterates through a cell's `chars[]` array without an upper bound, relying solely on a NUL terminator. When a terminal cell is filled with the maximum allowed characters (one base character and five combining marks), the underlying `libvterm` library returns the array without a NUL terminator. This causes the loop to read past the six-element array and append out-of-bounds data to a fixed-size buffer. An attacker can trigger this by running a program inside a `:terminal` window that outputs a specific byte sequence, resulting in an application crash (DoS). The vulnerability is fixed in version 9.2.0565 by adding a loop guard.
Affected products
- Vim Vim < 9.2.0565
Timeline
- 2026-05-30: patched: Patch 9.2.0565 released
- 2026-05-30: advisory: GitHub Security Advisory published
- 2026-06-11: disclosed: CVE published to NVD