CVE-2026-8997: heap overflow in vifm file manager
A heap buffer overflow in vifm's history merge process during state file saving can cause memory corruption or crashes; fixed after coordinated disclosure by CERT Polska.
CERT Polska coordinated the disclosure of CVE-2026-8997, a heap buffer overflow vulnerability affecting vifm, a vi/vim-inspired terminal file manager. The flaw arises during the history merge process when the application saves its state file (vifminfo.json). Release builds lack a runtime length check on history entries, meaning a crafted long path or command stored in the history could trigger memory corruption or crash the application.
All vifm releases from 0.12.1 through 0.14.3 inclusive are affected. The issue has been fixed via commit 23063c7. Researchers Michał Majchrowicz and Marcin Wyczechowski of AFINE are credited with the responsible vulnerability report, and CERT Polska facilitated the coordinated disclosure process.
There is no indication of active exploitation in the wild; this is a standard responsible-disclosure advisory for a memory-safety bug in a niche file manager utility. Users of affected vifm versions should update to the patched release to mitigate potential crashes or memory corruption risks.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8997
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free