MEDIUM
vifm
CVE published 2026-05-22
CVE-2026-8997
A heap buffer overflow vulnerability exists in vifm, a text-based file manager, during the history merge process when saving the state file (vifminfo.json). The issue arises from the lack of a runtime check on the length of history entries in release builds. This could potentially allow a crafted long path or command in the history to cause memory corruption or application crashes. The vulnerability affec [truncated]