Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed.. openSUSE security update: security update for vim ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20540-1 Rating: important References: * bsc#1259985 * bsc#1261191 * bsc#1261271 Cross-References: * CVE-2026-33412 * CVE-2026-34714 * CVE-2026-34982 CVSS scores: * CVE-2026-33412 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-33412 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-34714 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-34714 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-34982 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N * CVE-2026-34982 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for vim fixes the following issues: - CVE-2026-33412: command injection via newline in glob() (bsc#1259985). - CVE-2026-34714: crafted file can allow code execution (bsc#1261191). - CVE-2026-34982: Vim modeline bypass via various options (bsc#1261271). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-563=1 Package List: - openSUSE Leap 16.0: gvim-9.2.0280-160000.1.1 vim-9.2.0280-160000.1.1 vim-data-9.2.0280-160000.1.1 vim-data-common-9.2.0280-160000.1.1 vim-small-9.2.0280-160000.1.1 xxd-9.2.0280-160000.1.1 References: * https://www.suse.com/security/cve/CVE-2026-33412.html *https://www.suse.com/security/cve/CVE-2026-34714.html * https://www.suse.com/security/cve/CVE-2026-34982.html . This security advisory details important updates for vim on openSUSE, addressing command injection and code execution risks.. openSUSE security update, vim patch, command injection fix, code execution vulnerability, modeline bypass issue. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities can now be installed.. # Security update for vim Announcement ID: SUSE-SU-2026:21130-1 Release Date: 2026-04-14T07:55:35Z Rating: important References: * bsc#1259985 * bsc#1261191 * bsc#1261271 Cross-References: * CVE-2026-33412 * CVE-2026-34714 * CVE-2026-34982 CVSS scores: * CVE-2026-33412 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33412 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-33412 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N * CVE-2026-33412 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-34714 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-34714 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-34714 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-34714 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-34982 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-34982 ( SUSE ): 8.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N * CVE-2026-34982 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for vim fixes the following issues: * Update to 9.2.0280 * CVE-2026-33412: command injection via newline in glob() (bsc#1259985). * CVE-2026-34714: crafted file can allow code execution (bsc#1261191). * CVE-2026-34982: Vim modeline bypass via various options (bsc#1261271). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patchSUSE-SLE-Micro-Extras-6.0-665=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * vim-debugsource-9.2.0280-1.1 * vim-9.2.0280-1.1 * vim-debuginfo-9.2.0280-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33412.html * https://www.suse.com/security/cve/CVE-2026-34714.html * https://www.suse.com/security/cve/CVE-2026-34982.html * https://bugzilla.suse.com/show_bug.cgi?id=1259985 * https://bugzilla.suse.com/show_bug.cgi?id=1261191 * https://bugzilla.suse.com/show_bug.cgi?id=1261271 . Essential update for vim addressing important command injection, code execution, and modeline bypass vulnerabilities.. vim security update, SUSE vulnerabilities, command injection fix, code execution risk. . Severity: Important. LinuxSecurity.com Team
MGASA-2026-0083 - Updated vim packages fix security vulnerabilities. MGASA-2026-0083 - Updated vim packages fix security vulnerabilities Publication date: 06 Apr 2026 URL: https://advisories.mageia.org/MGASA-2026-0083.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-34982, CVE-2026-35177 Description: Vim modeline bypass via various options affects Vim < 9.2.0276. (CVE-2026-34982) Path traversal issue with zip.vim in Vim < v9.2.0280. (CVE-2026-35177) References: - https://bugs.mageia.org/show_bug.cgi?id=35308 - https://www.openwall.com/lists/oss-security/2026/03/31/14 - https://www.openwall.com/lists/oss-security/2026/04/01/1 - https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9 - https://www.openwall.com/lists/oss-security/2026/04/01/4 - https://github.com/vim/vim/security/advisories/GHSA-jc86-w7vm-8p24 - https://www.cve.org/CVERecord?id=CVE-2026-34982 - https://www.cve.org/CVERecord?id=CVE-2026-35177 SRPMS: - 9/core/vim-9.2.280-1.mga9 . Updated vim packages in Mageia fix important security issues, including modeline bypass and path traversal vulnerabilities.. Vim Mageia Security Advisory Path Traversal Modeline Bypass. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.