# vifm heap overflow fixed in 0.14.4

Published: 2026-05-22 · Severity: medium
Canonical: https://vorant.io/reports/4e019041-065c-5990-80f6-f5bb688e7ced/vifm-heap-overflow-fixed-in-0-14-4

> A heap buffer overflow in vifm file manager (CVE-2026-8997) affects versions 0.12.1–0.14.3, allowing crafted history entries to corrupt memory or crash the application.

CERT Polska disclosed CVE-2026-8997, a heap buffer overflow vulnerability in vifm, a terminal-based file manager. The flaw occurs during the history merge process when saving the state file (vifminfo.json). Release builds lack runtime checks on history entry lengths, allowing an attacker to craft long path or command entries in the history that trigger memory corruption or application crashes.

Versions 0.12.1 through 0.14.3 are affected. The issue was remediated in commit 23063c7. The vulnerability was reported responsibly by researchers Michał Majchrowicz and Marcin Wyczechowski from AFINE.

Organizations using vifm should update to version 0.14.4 or later. The vulnerability requires local access or social engineering to deliver a malicious history file, limiting the scope of exploitation to environments where attackers can influence user files or history state.

## Mentioned in this report

- Vulnerabilities: CVE-2026-8997

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-8997

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4e019041-065c-5990-80f6-f5bb688e7ced/vifm-heap-overflow-fixed-in-0-14-4.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
