CVE-2026-57452
CVE-2026-57452: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityMedium4.7
Medium [CVE-2026-57452] Out-of-bounds Read with libsodium-encrypted Files
CVE-2026-57452Source published Source updated
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (xchacha20poly1305, requires the +sodium feature) whose body is shorter than a single libsodium secretstream header, an unsigned length calculation underflows and a subsequent decryption call reads far past the end of the input buffer, crashing Vim. This vulnerability is fixed in 9.2.0671. When opening a specially crafted encrypted file using the VimCrypt~04! or VimCrypt~05! methods, an attacker could trigger an unsigned length calculation error. This issue leads to an out-of-bounds read, causing Vim to crash and resulting in a denial of service. This Moderate impact vulnerability in Vim arises from an out-of-bounds read when processing a…
- Affected products in this advisory
- Red Hat Hardened Images
- Red Hat Enterprise Linux 6
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 9
2 more entries in the full advisory.
- Source-reported affected versions
- < 9.2.0671
- Source-reported fixed versions
- 9.2.0671
- vim-main-9.2.725-1.hum1
- RHSA-2026:30267
- Mitigation guidance
- Ensure the spell checker is turned off by running :set nospell within Vim. Do not open untrusted or suspicious files—particularly those encrypted with libsodium methods (VimCrypt~04! or VimCrypt~05!)—within the Vim editor. This prevents the execution of the vulnerable decryption routine
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.