Bug 2492968 (CVE-2026-57455)

Summary: CVE-2026-57455 vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo()
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, kshier, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, stcannon, suppawar, teagle, vlaad, watson-tool-maintainers, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A memory corruption flaw in Vim allows an attacker to cause a Denial of Service (DoS). When a SOFO-based spell language is active, providing an excessively long word to the spell checker triggers a stack out-of-bounds write in the spell_soundfold_sofo() function, causing the editor to crash.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2495906    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-25 16:01:42 UTC
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri with no upper bound and terminates only on the input NUL, writing one byte per input byte into the MAXWLEN-element stack buffer the caller provides. A word longer than MAXWLEN, passed to soundfold() (or reached via sound-based spell suggestion) while a SOFO-based spell language is active, therefore writes past the end of that buffer. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0698.

Comment 3 errata-xmlrpc 2026-07-29 17:34:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:47982 https://access.redhat.com/errata/RHSA-2026:47982

Comment 4 errata-xmlrpc 2026-07-30 10:48:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:48703 https://access.redhat.com/errata/RHSA-2026:48703

Comment 5 errata-xmlrpc 2026-07-30 13:50:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:48650 https://access.redhat.com/errata/RHSA-2026:48650

Comment 6 errata-xmlrpc 2026-08-17 02:29:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:55431 https://access.redhat.com/errata/RHSA-2026:55431

Comment 7 errata-xmlrpc 2026-08-18 12:25:34 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769

Comment 8 Jon Orris 2026-09-17 19:08:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:68711 https://access.redhat.com/errata/RHSA-2026:68711

Comment 9 Jon Orris 2026-09-21 02:45:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION

Via RHSA-2026:69128 https://access.redhat.com/errata/RHSA-2026:69128

Comment 10 Jon Orris 2026-09-23 15:54:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:70818 https://access.redhat.com/errata/RHSA-2026:70818

Comment 11 Jon Orris 2026-09-28 11:30:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:72466 https://access.redhat.com/errata/RHSA-2026:72466

Comment 12 Jon Orris 2026-09-28 11:55:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:72465 https://access.redhat.com/errata/RHSA-2026:72465