Executive brief
vifm, a terminal-based file manager, is vulnerable to a memory corruption issue when processing its history state file. An attacker could potentially cause the application to crash or behave unexpectedly by providing a specially crafted long file path or command that gets saved into the application's history. This could lead to a loss of application availability or a disruption of local operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in vifm's trie implementation within src/utils/trie.c. The vulnerability is triggered during the history merge process when saving the vifminfo.json state file. The root cause is an incorrect reliance on assert() statements for bounds checking; since asserts are typically disabled in release builds, the application fails to validate the length of history entries (paths or commands) before processing them. A local attacker can exploit this by introducing a long string into the history, leading to memory corruption or a Denial of Service (crash). The issue was addressed in commit 23063c7 by removing the fixed buffer limitation and ensuring the trie can handle keys of arbitrary length.
Affected products
- vifm vifm 0.12.1 to 0.14.3
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory
- 2026-05-22: patched: Fixed in commit 23063c741f15a85621fd232dfc3ac5b779f6910d