Junglewise Threat Intelligence

CVE-2026-8997: vifm heap buffer overflow in history merge process

CVE-2026-8997 · Severity: info · CVSS 4.8 · Published 2026-05-22

Executive brief

vifm, a terminal-based file manager, is vulnerable to a memory corruption issue when processing its history state file. An attacker could potentially cause the application to crash or behave unexpectedly by providing a specially crafted long file path or command that gets saved into the application's history. This could lead to a loss of application availability or a disruption of local operations.

Technical details

A heap-based buffer overflow (CWE-122) exists in vifm's trie implementation within src/utils/trie.c. The vulnerability is triggered during the history merge process when saving the vifminfo.json state file. The root cause is an incorrect reliance on assert() statements for bounds checking; since asserts are typically disabled in release builds, the application fails to validate the length of history entries (paths or commands) before processing them. A local attacker can exploit this by introducing a long string into the history, leading to memory corruption or a Denial of Service (crash). The issue was addressed in commit 23063c7 by removing the fixed buffer limitation and ensuring the trie can handle keys of arbitrary length.

Affected products

  • vifm vifm 0.12.1 to 0.14.3

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory
  • 2026-05-22: patched: Fixed in commit 23063c741f15a85621fd232dfc3ac5b779f6910d

References