Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

openSUSE 15.5 vim Moderate Command Injection Advisory 2026-2029-1

opensuse
Calendar Grey May 20, 2026
Scroller Opensuse
Find the latest security advisory for openSUSE 15.5 addressing a moderate command injection issue in vim.
An update that solves one vulnerability can now be installed.

Description

This update for vim fixes the following issue:

Security fixes:

* CVE-2026-39881: command injection in NetBeans interface can lead to

arbitrary file reads and writes (bsc#1261833).

Other fixes:

* Update to 9.2.0398.

* 9.2.0398: MS-Windows: missing strptime() support

* 9.2.0397: tabpanel: double-click opens a new tab

* 9.2.0396: tests: Test_error_callback_terminal is flaky on macOS

* 9.2.0395: tests: Test_backupskip() may read from $HOME

* 9.2.0394: xxd: offsets greater than LONG_MAX print as negative

* 9.2.0393: MS-Windows: link error with XPM support on UCRT64

* 9.2.0392: tests: Some tests are flaky

* 9.2.0391: tests: Comment in test_vim9_cmd breaks syntax highlighting

* 9.2.0390: filetype: some Beancount files are not recognized

* 9.2.0389: DECRQM still leaves stray "pp" on Apple Terminal.app

* 9.2.0388: strange indent in update_topline()

* 9.2.0387: DECRQM request may leave stray chars in terminal

* 9.2.0386: No scroll/scrollbar support in the...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro 5.5

zypper in -t patch SUSE-SLE-Micro-5.5-2026-2029=1

* openSUSE Leap 15.5

zypper in -t patch SUSE-2026-2029=1

* Basesystem Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2029=1

* Desktop Applications Module 15-SP7

zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2029=1

Package List

* SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64)

* vim-small-9.2.0398-150500.20.49.1

* vim-small-debuginfo-9.2.0398-150500.20.49.1

* vim-debugsource-9.2.0398-150500.20.49.1

* vim-debuginfo-9.2.0398-150500.20.49.1

* SUSE Linux Enterprise Micro 5.5 (noarch)

* vim-data-common-9.2.0398-150500.20.49.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586)

* gvim-9.2.0398-150500.20.49.1

* gvim-debuginfo-9.2.0398-150500.20.49.1

* vim-debuginfo-9.2.0398-150500.20.49.1

* vim-small-debuginfo-9.2.0398-150500.20.49.1

* vim-small-9.2.0398-150500.20.49.1

* vim-debugsource-9.2.0398-150500.20.49.1

* vim-9.2.0398-150500.20.49.1

* openSUSE Leap 15.5 (noarch)

* vim-data-common-9.2.0398-150500.20.49.1

* vim-data-9.2.0398-150500.20.49.1

* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)

* vim-debuginfo-9.2.0398-150500.20.49.1

* vim-small-9.2.0398-150500.20.49.1

* vim-9.2.0398-150500.20.49.1

* vim-debugsource-9.2.0398-150500.20.49.1

* vim-small-debuginfo-9.2.0398-150500.20.49.1

* Basesystem Module 15-SP7...

Read the Full Advisory

References

* bsc#1261833

## References:

* https://www.suse.com/security/cve/CVE-2026-39881.html

* https://bugzilla.suse.com/show_bug.cgi?id=1261833

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2029-1
Release Date: 2026-05-20T09:18:19Z
Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.