{"id":"CVE-2026-8997","summary":"Heap Buffer Overflow in vifm","details":"vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the history to cause memory corruption or application crashes.\nReleases from 0.12.1 to 0.14.3 (including) are considered vulnerable. This issue was fixed in commit 23063c7","modified":"2026-08-12T16:09:28.812740Z","published":"2026-05-22T13:26:17.904Z","related":["openSUSE-SU-2026:10928-1"],"database_specific":{"cna_assigner":"CERT-PL","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8997.json"},"references":[{"type":"WEB","url":"https://github.com/vifm/vifm/"},{"type":"ADVISORY","url":"https://cert.pl/en/posts/2026/05/CVE-2026-8997"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8997.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8997"},{"type":"FIX","url":"https://github.com/vifm/vifm/commit/23063c741f15a85621fd232dfc3ac5b779f6910d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vifm/vifm","events":[{"introduced":"ba928c66d708108666cf51ad5e905d4dd565af17"},{"fixed":"23063c741f15a85621fd232dfc3ac5b779f6910d"}],"database_specific":{"extracted_events":[{"introduced":"0.12.1"},{"last_affected":"0.14.3"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8997.json","vanir_signatures_modified":"2026-08-12T16:09:28Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["104702481591007110229662474953162703402","193713114147484270815220125247958422292","197792957414472833909984436290024555682","96101009217859846317737504947546369247","150108905041283934830270668719981492515","37117665919389689336814562589556457720"],"threshold":0.9},"id":"CVE-2026-8997-69addbfb","signature_type":"Line","signature_version":"v1","source":"https://github.com/vifm/vifm/commit/23063c741f15a85621fd232dfc3ac5b779f6910d","target":{"file":"tests/utils/trie.c"}},{"signature_version":"v1","source":"https://github.com/vifm/vifm/commit/23063c741f15a85621fd232dfc3ac5b779f6910d","target":{"file":"src/utils/trie.c"},"deprecated":false,"digest":{"line_hashes":["273602623691499732143978570081954474683","213718699141295272471346177543047731432","137063631675337397181647075241150022024","298531298008248054901180269639597951788","294948752307748782359621052729117789406","933176558147121840197093288394751703","139588446134025557868946671351419019187","120625306313110739524873807580171861366","252075476075312133679024605275724575956","312324746990875763726230258398266530572","336149655328772949395814481727333609600","326554573415492812734754316553606749579","12291985008428645356107876066833232277","198968721056482972334880817310979662476","25110457906117253290072438102599869567","29471038899299986068262601256795716187"],"threshold":0.9},"id":"CVE-2026-8997-9edff0be","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/vifm/vifm/commit/23063c741f15a85621fd232dfc3ac5b779f6910d","target":{"file":"src/utils/trie.c","function":"alloc_string"},"deprecated":false,"digest":{"function_hash":"38867121710186556280807366723007625968","length":674},"id":"CVE-2026-8997-afcbf65b","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}