VDB
ALPINE-CVE-2026-28420
ALPINE-CVE-2026-28420
PUBLISHED
CVSS 4.400000095367432 MEDIUM
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
Risk Scores
CVSS v3.1
4.400000095367432
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.23 | vim | 7.2.284-r0, 7.2.394-r0, 7.2.394-r1 |
Timeline
- Feb 27, 2026 CVE Published
- Mar 1, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch