Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Oracle Linux 10 vim Important Code Injection Issues ELSA-2026-38509

oracle
Calendar Grey July 22, 2026
Scroller Oracle
Oracle Linux 10 updates for vim address critical code execution risks, ensuring software integrity and security.
Oracle Linux has released security updates for Vim packages in version 10, addressing multiple vulnerabilities including code and command injection issues linked to various CVEs.

Summary

[9.1.083-9.0.1.el10_2.7] - Remove upstream references [Orabug: 31197557] [2:9.1.083-9.7] - RHEL-186660 CVE-2026-47162 vim: netrw code injection via NetrwBookHistSave() - RHEL-186671 CVE-2026-52858 vim: possible code execution with python3complete [2:9.1.083-9.6] - RHEL-185867 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin [2:9.1.083-9.5] - RHEL-178233 CVE-2026-46483 vim: command injection in tar plugin [2:9.1.083-9.4] - RHEL-171481 CVE-2026-41411 vim: Command injection via backticks in tag files [2:9.1.083-9.3] - RHEL-170123 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:9.1.083-9.2] - Resolves: RHEL-164952 vim: arbitrary command execution via modeline sandbox bypass [2:9.1.083-9.1] - RHEL-159616 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function

SRPMs

http://oss.oracle.com/ol10/SRPMS-updates/vim-9.1.083-9.0.1.el10_2.7.src.rpm

x86_64

vim-X11-9.1.083-9.0.1.el10_2.7.x86_64.rpm vim-common-9.1.083-9.0.1.el10_2.7.x86_64.rpm vim-data-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-enhanced-9.1.083-9.0.1.el10_2.7.x86_64.rpm vim-filesystem-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-minimal-9.1.083-9.0.1.el10_2.7.x86_64.rpm xxd-9.1.083-9.0.1.el10_2.7.x86_64.rpm

aarch64

vim-X11-9.1.083-9.0.1.el10_2.7.aarch64.rpm vim-common-9.1.083-9.0.1.el10_2.7.aarch64.rpm vim-data-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-enhanced-9.1.083-9.0.1.el10_2.7.aarch64.rpm vim-filesystem-9.1.083-9.0.1.el10_2.7.noarch.rpm vim-minimal-9.1.083-9.0.1.el10_2.7.aarch64.rpm xxd-9.1.083-9.0.1.el10_2.7.aarch64.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-46483 CVE-2026-47162 CVE-2026-47167 CVE-2026-52858

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.