VORANT. Threat Intelligence Sign in Get the full feed

vifm file manager versions 0.12.1-0.14.3 contain a heap buffer overflow (CVE-2026-8997)…

medium vulnerability

vifm file manager versions 0.12.1-0.14.3 contain a heap buffer overflow (CVE-2026-8997) triggered by crafted history entries during state-file save, potentially causing crashes or memory corruption.

CERT Polska coordinated disclosure of CVE-2026-8997, a heap buffer overflow vulnerability in vifm, a terminal-based file manager. The flaw exists in the history merge process when the application saves its state file (vifminfo.json). Due to missing runtime length checks on history entries in release builds, an attacker who can control or inject a crafted long path or command into the history can trigger memory corruption or cause the application to crash.

All vifm releases from version 0.12.1 through 0.14.3 are affected. The issue has been addressed in commit 23063c7. The vulnerability was responsibly reported by researchers from AFINE and coordinated through CERT Polska's vulnerability disclosure process.

While the vulnerability requires local access or the ability to influence history entries, organizations using vifm in multi-user environments or processing untrusted data should prioritize patching. The heap overflow could potentially be leveraged for code execution depending on exploit primitives, though no active exploitation has been reported.

Mentioned in this report

Vulnerabilities CVE-2026-8997

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8997

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free