Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 561
Alerts This Week
Warning Icon 1 561

Oracle Linux 10 vim Moderate Command Injection Advisory ELSA-2026-28210

oracle
Calendar Grey July 28, 2026
Scroller Oracle
Oracle Linux 10 updates for vim address various security flaws including command injection and arbitrary code execution risks.
Oracle released updates for Oracle Linux 10 addressing multiple security vulnerabilities in Vim through various RPMs, mitigating risks associated with command execution and code in...

Summary

[9.1.083-9.0.1.el10_2.7] - Remove upstream references [Orabug: 31197557] [2:9.1.083-9.7] - RHEL-186660 CVE-2026-47162 vim: netrw code injection via NetrwBookHistSave() - RHEL-186671 CVE-2026-52858 vim: possible code execution with python3complete [2:9.1.083-9.6] - RHEL-185867 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin [2:9.1.083-9.5] - RHEL-178233 CVE-2026-46483 vim: command injection in tar plugin [2:9.1.083-9.4] - RHEL-171481 CVE-2026-41411 vim: Command injection via backticks in tag files [2:9.1.083-9.3] - RHEL-170123 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:9.1.083-9.2] - Resolves: RHEL-164952 vim: arbitrary command execution via modeline sandbox bypass [2:9.1.083-9.1] - RHEL-159616 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/vim-9.1.083-9.0.1.el10_2.7.src.rpm

x86_64

vim-X11-9.1.083-9.0.1.el10_2.7.x86_64.rpm vim-common-9.1.083-9.0.1.el10_2.7.x86_64.rpm vim-data-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-enhanced-9.1.083-9.0.1.el10_2.7.x86_64.rpm vim-filesystem-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-minimal-9.1.083-9.0.1.el10_2.7.x86_64.rpm xxd-9.1.083-9.0.1.el10_2.7.x86_64.rpm

aarch64

vim-X11-9.1.083-9.0.1.el10_2.7.aarch64.rpm vim-common-9.1.083-9.0.1.el10_2.7.aarch64.rpm vim-data-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-enhanced-9.1.083-9.0.1.el10_2.7.aarch64.rpm vim-filesystem-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-minimal-9.1.083-9.0.1.el10_2.7.aarch64.rpm xxd-9.1.083-9.0.1.el10_2.7.aarch64.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-41411

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.