Impact
A malformed spell file that begins with an SN_SAL section followed by an SN_SOFO section triggers a reuse of the sl_sal_first[] array without resetting values set by set_sal_first(). This causes under‑counted mapping lists and allows attacker‑influenced writes beyond the bounds of a heap allocation. The result is a heap buffer overflow that corrupts memory. The specific higher‑level consequences of that corruption, such as code execution or denial of service, are not described in the CVE details.
Affected Systems
Vim prior to version 9.2.0846 is vulnerable. This includes all releases before 9.2.0846 available for Linux, Windows, macOS, and other platforms that install Vim from source or package managers.
Risk and Exploitability
The CVSS score of 8.5 classifies this flaw as High severity. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is triggered by loading a spell file, a user‑controlled input. The exact attack vector (local or remote) and the conditions needed for successful exploitation are not specified in the advisory. The vulnerability could lead to memory corruption; further impacts depend on the environment and are not detailed.
OpenCVE Enrichment