Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for vim fixes the following issues:
Update to version 9.2.0780.
Security issues fixed:
- CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194).
- CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195).
- CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193).
Other updates and bugfixes:
- Version 9.2.0780 changelog:
* filetype detect missing from completion (9.2.0726).
* popup images not rendered correctly when unfocused (9.2.0727).
* filetype: supertux info pattern is relative to current dir
(9.2.0728).
* % skips parens on continued quoted lines (9.2.0729).
* GTK4 GUI tabline is not updated (9.2.0730).
* GTK4 GUI scrollbar size not updated when restoring a session
(9.2.0731).
* session: terminal restored using absolute columns/rows (9.2.0732).
* GTK3: GUI slow on X11 since dropping the alpha channel...
Read the Full Advisory- openSUSE Leap 16.0:
gvim-9.2.0780-160000.1.1
vim-9.2.0780-160000.1.1
vim-data-9.2.0780-160000.1.1
vim-data-common-9.2.0780-160000.1.1
vim-small-9.2.0780-160000.1.1
xxd-9.2.0780-160000.1.1
* bsc#1271193
* bsc#1271194
* bsc#1271195
References:
* https://www.suse.com/security/cve/CVE-2026-59856.html
* https://www.suse.com/security/cve/CVE-2026-59857.html
* https://www.suse.com/security/cve/CVE-2026-59858.html
Get the latest Linux and open source security news straight to your inbox.