VDB

DEBIAN-CVE-2026-26269

DEBIAN-CVE-2026-26269 PUBLISHED CVSS 7.5 HIGH

Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteration into a 64-byte stack buffer (keybuf) with no bounds check. A malicious NetBeans server can overflow keybuf with a single specialKeys command. The issue has been fixed as of Vim patch v9.1.2148.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11vim9.1.0496-1, 9.1.0377-1, 9.1.0374-1
Debian:12vim9.2.0119-1, 2:9.0.1378-2, 2:9.0.1378-2+deb12u2
Debian:13vim2:9.1.1385-1, 9.1.1766-1, 9.1.1385-1
Debian:14vim9.1.2141-1, 9.1.2103-1, 9.1.1882-1

Timeline

  • Feb 13, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›