{"id":"DEBIAN-CVE-2026-57454","details":"Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose offset and length point outside the line's property data. When Vim restores or displays such a line it converts the offset into a pointer and reads the virtual text without bounds checking, causing an out-of-bounds read that can crash Vim or disclose adjacent heap memory. This vulnerability is fixed in 9.2.0679.","modified":"2026-08-27T23:06:13.658593112Z","published":"2026-06-25T16:16:42.647Z","upstream":["CVE-2026-57454"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-57454"}],"affected":[{"package":{"name":"vim","ecosystem":"Debian:14","purl":"pkg:deb/debian/vim?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:9.2.0782-1"}]}],"versions":["2:9.1.1230-2","2:9.1.1385-1","2:9.1.1766-1","2:9.1.1829-1","2:9.1.1846-1","2:9.1.1882-1","2:9.1.2103-1","2:9.1.2141-1","2:9.2.0119-1","2:9.2.0136-1","2:9.2.0218-1","2:9.2.0315-1","2:9.2.0338-1","2:9.2.0355-1","2:9.2.0428-1","2:9.2.0461-1","2:9.2.0524-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-57454.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H"}]}