<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 12:10:07 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-55892 — Vim: Out-of-bounds Write in Spell File Prefix Dump</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-55892</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vim&lt;/p&gt;
&lt;p&gt;Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; vim&lt;/p&gt;
&lt;p&gt;Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-55892</guid>
    </item>
    <item>
      <title>USN-8500-1 — vim vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8500-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: vim, Ubuntu:Pro:16.04:LTS: vim, Ubuntu:Pro:18.04:LTS: vim, Ubuntu:Pro:20.04:LTS: vim, Ubuntu:22.04:LTS: vim, Ubuntu:24.04:LTS: vim, Ubuntu:25.10: vim, Ubuntu:26.04:LTS: vim&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled path traversal in the
zip.vim plugin. An attacker could possibly use this issue to overwrite
arbitrary files. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2026-35177)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled depth tracking when
processing spell files. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-55693, CVE-2026-55892)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled filename escaping in the
netrw plugin. An attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10,
and Ubuntu 26.04 LTS. (CVE-2026-55895)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled length calculations when
opening encrypted files. An attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-57452)&lt;/p&gt;
&lt;p&gt;Dhruv Vishesh Gupta discovered that Vim incorrectly handled quoting of
archive entry names. An attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-57453)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled bounds checking when
translating words through a byte map. An attacker could possibly use this
issue to cause a denial of service.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: vim, Ubuntu:Pro:16.04:LTS: vim, Ubuntu:Pro:18.04:LTS: vim, Ubuntu:Pro:20.04:LTS: vim, Ubuntu:22.04:LTS: vim, Ubuntu:24.04:LTS: vim, Ubuntu:25.10: vim, Ubuntu:26.04:LTS: vim&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled path traversal in the
zip.vim plugin. An attacker could possibly use this issue to overwrite
arbitrary files. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.
(CVE-2026-35177)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled depth tracking when
processing spell files. An attacker could possibly use this issue to cause
a denial of service. (CVE-2026-55693, CVE-2026-55892)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled filename escaping in the
netrw plugin. An attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10,
and Ubuntu 26.04 LTS. (CVE-2026-55895)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled length calculations when
opening encrypted files. An attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu
24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-57452)&lt;/p&gt;
&lt;p&gt;Dhruv Vishesh Gupta discovered that Vim incorrectly handled quoting of
archive entry names. An attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-57453)&lt;/p&gt;
&lt;p&gt;It was discovered that Vim incorrectly handled bounds checking when
translating words through a byte map. An attacker could possibly use this
issue to cause a denial of service.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8500-1</guid>
    </item>
  </channel>
</rss>
