Unrated severityNVD Advisory· Published Jun 26, 2026
Debian vim: Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim ope…
CVE-2026-57452
Description
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (xchacha20poly1305, requires the +sodium feature) whose body is shorter than a single libsodium secretstream header, an unsigned length calculation underflows and a subsequent decryption call reads far past the end of the input buffer, crashing Vim. This vulnerability is fixed in 9.2.0671.
Affected products
1Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.