Bug 2492980 (CVE-2026-55693) - CVE-2026-55693 vim: Vim: Out-of-bounds Write in Spell File Word Count
Summary: CVE-2026-55693 vim: Vim: Out-of-bounds Write in Spell File Word Count
Keywords:
Status: NEW
Alias: CVE-2026-55693
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2498957
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-25 16:02 UTC by OSIDB Bzimport
Modified: 2026-07-30 13:50 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:47982 0 None None None 2026-07-29 17:34:13 UTC
Red Hat Product Errata RHSA-2026:48650 0 None None None 2026-07-30 13:50:52 UTC
Red Hat Product Errata RHSA-2026:48703 0 None None None 2026-07-30 10:48:05 UTC

Description OSIDB Bzimport 2026-06-25 16:02:46 UTC
Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

Comment 2 errata-xmlrpc 2026-07-29 17:34:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:47982 https://access.redhat.com/errata/RHSA-2026:47982

Comment 3 errata-xmlrpc 2026-07-30 10:48:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:48703 https://access.redhat.com/errata/RHSA-2026:48703

Comment 4 errata-xmlrpc 2026-07-30 13:50:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:48650 https://access.redhat.com/errata/RHSA-2026:48650


Note You need to log in before you can comment on or make changes to this bug.