PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73074 vim CVE debrief

A vulnerability in Vim, a command-line text editor, allows for a heap-based buffer overflow when handling text properties. This issue, fixed in version 9.2.0841, has a CVSS score of 7.1 and is considered HIGH severity. The vulnerability arises from the prop_add_one() function in src/textprop.c, which incorrectly handles property counts, leading to potential denial of service or code execution. Defenders should assess exposure and prioritize patching or upgrading to version 9.2.0841 or later.

Vendor
vim
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Defenders responsible for managing and securing Vim installations, particularly in environments where Vim is used for editing text files, should assess exposure and prioritize patching or upgrading to version 9.2.0841 or later.

Why it matters

CVE-2026-73074 is a high-severity vulnerability in Vim that requires patching or upgrading to version 9.2.0841 or later to prevent potential heap-based buffer overflows. Defenders should prioritize patching, review inventory, and monitor for exploitation attempts.

  • Potential for heap-based buffer overflow leading to denial of service or code execution
  • Need for verification of affected versions and deployment of patched versions
  • Importance of monitoring for potential exploitation attempts targeting this vulnerability
  • Requirement for inventory checks and updates to ensure patched versions are deployed

Technical summary

The prop_add_one() function in src/textprop.c of Vim uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue, fixed in version 9.2.0841, can lead to a heap-based buffer overflow and potential denial of service or code execution. Defenders should prioritize patching or upgrading to Vim version 9.2.0841 or later to prevent potential heap-based buffer overflows.

Defensive priority

Defenders should prioritize patching or upgrading to Vim version 9.2.0841 or later to prevent potential heap-based buffer overflows.

Recommended defensive actions

  • Patch or upgrade to Vim version 9.2.0841 or later
  • Review and update inventory of Vim installations to ensure version 9.2.0841 or later is deployed
  • Monitor for potential exploitation attempts targeting this vulnerability
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and affected versions. The issue is caused by the prop_add_one() function in src/textprop.c using the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. The fix is included in Vim version 9.2.0841. Defenders should verify affected versions and ensure patched versions are deployed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73074 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73074

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73074 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73074

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.