Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 431
Alerts This Week
Warning Icon 1 431

SUSE Linux Micro vim Important Security Update 2026-22740-1

suse
Calendar Grey July 22, 2026
Scroller Suse
A security update for SUSE Linux Micro addressing three important issues in vim with risks of code execution and memory leaks.
SUSE has released an update for vim addressing three critical vulnerabilities, which allow arbitrary code execution and out-of-bounds writes, alongside various bug fixes and enhanc...

Summary

## This update for vim fixes the following issues: Update to version 9.2.0780. Security issues fixed: * CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194). * CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195). * CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193). Other updates and bugfixes: * Version 9.2.0780 changelog: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730).

References

* bsc#1271193

* bsc#1271194

* bsc#1271195

Cross-

* CVE-2026-59856

* CVE-2026-59857

* CVE-2026-59858

CVSS scores:

* CVE-2026-59856 ( SUSE ): 8.4

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-59856 ( NVD ): 8.4

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

* CVE-2026-59857 ( SUSE ): 5.6

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22740-1
Release Date: 2026-07-18T11:52:07Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.