Executive brief
Vim is a widely used open-source text editor. A vulnerability in its spell-checking component allows the application to crash or potentially execute unauthorized code when processing specially crafted, long words. This occurs when the editor is configured with specific language settings and 8-bit encodings, potentially leading to a loss of availability or a compromise of the user's session if they interact with malicious input.
Technical details
A stack-based out-of-bounds write exists in the single-byte branch of spell_soundfold_sofo() in src/spell.c. The vulnerability is caused by a copy loop that lacks an upper-bound check against the MAXWLEN-element stack buffer, terminating only on a NUL byte. An attacker can trigger this by providing a word longer than 253 bytes to the soundfold() function or via sound-based spell suggestions while a SOFO-based spell language and a non-multibyte encoding (e.g., latin1) are active. This results in stack corruption and a process crash. The issue is fixed in version 9.2.0698 by adding an abort condition to the loop to validate buffer size.
Affected products
- Vim Vim < 9.2.0698
Timeline
- 2026-06-21: disclosed: Vulnerability reported and analyzed by Cipher/Causal Security
- 2026-06-21: patched: Fixed in patch 9.2.0698
- 2026-06-25: advisory: NVD and GitHub advisories published