Junglewise Threat Intelligence

CVE-2026-57455: Vim stack out-of-bounds write in spell_soundfold_sofo

CVE-2026-57455 · Severity: info · CVSS 5.4 · Published 2026-06-25

Technologies: Vim. Vendors: Vim.

Executive brief

Vim is a widely used open-source text editor. A vulnerability in its spell-checking component allows the application to crash or potentially execute unauthorized code when processing specially crafted, long words. This occurs when the editor is configured with specific language settings and 8-bit encodings, potentially leading to a loss of availability or a compromise of the user's session if they interact with malicious input.

Technical details

A stack-based out-of-bounds write exists in the single-byte branch of spell_soundfold_sofo() in src/spell.c. The vulnerability is caused by a copy loop that lacks an upper-bound check against the MAXWLEN-element stack buffer, terminating only on a NUL byte. An attacker can trigger this by providing a word longer than 253 bytes to the soundfold() function or via sound-based spell suggestions while a SOFO-based spell language and a non-multibyte encoding (e.g., latin1) are active. This results in stack corruption and a process crash. The issue is fixed in version 9.2.0698 by adding an abort condition to the loop to validate buffer size.

Affected products

  • Vim Vim < 9.2.0698

Timeline

  • 2026-06-21: disclosed: Vulnerability reported and analyzed by Cipher/Causal Security
  • 2026-06-21: patched: Fixed in patch 9.2.0698
  • 2026-06-25: advisory: NVD and GitHub advisories published

References

Related threats