| Summary | vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the history to cause memory corruption or application crashes. |
|---|---|
| Publication Date | May 22, 2026, 11:16 p.m. |
| Registration Date | May 27, 2026, 4:05 a.m. |
| Last Update | May 23, 2026, 1:16 a.m. |