Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 538
Alerts This Week
Warning Icon 1 538

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 372 articles for you...
172

Ubuntu 26.04 LTS Vim Denial of Service Risk with Arbitrary Commands

Several security issues were fixed in Vim.. ========================================================================== Ubuntu Security Notice USN-8541-1 July 14, 2026 vim vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Vim. Software Description: - vim: Vi IMproved - enhanced vi editor Details: Hirohito Higashi discovered that Vim incorrectly escaped class or trait names when performing PHP omni-completion. An attacker could possibly use this issue to trick a user into opening a specially crafted PHP file and executing arbitrary commands. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59856) Hirohito Higashi discovered that Vim incorrectly handled sound-folding of certain words when using a spell file. An attacker could possibly use this issue to cause Vim to crash, resulting in a denial of service. (CVE-2026-59857) It was discovered that Vim incorrectly escaped certain tags file fields when performing C omni-completion. An attacker could possibly use this issue to trick a user into opening a specially crafted file and executing arbitrary commands. (CVE-2026-59858) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS vim 2:9.1.2141-1ubuntu4.7 vim-common 2:9.1.2141-1ubuntu4.7 vim-gtk3 2:9.1.2141-1ubuntu4.7 vim-gui-common 2:9.1.2141-1ubuntu4.7 vim-motif 2:9.1.2141-1ubuntu4.7 vim-nox 2:9.1.2141-1ubuntu4.7 vim-runtime 2:9.1.2141-1ubuntu4.7 vim-tiny 2:9.1.2141-1ubuntu4.7 xxd 2:9.1.2141-1ubuntu4.7 Ubuntu 24.04 LTS vim 2:9.1.0016-1ubuntu7.18 vim-athena 2:9.1.0016-1ubuntu7.18 vim-common 2:9.1.0016-1ubuntu7.18 vim-gtk3 2:9.1.0016-1ubuntu7.18 vim-gui-common 2:9.1.0016-1ubuntu7.18 vim-motif 2:9.1.0016-1ubuntu7.18 vim-nox 2:9.1.0016-1ubuntu7.18 vim-runtime 2:9.1.0016-1ubuntu7.18 vim-tiny 2:9.1.0016-1ubuntu7.18 xxd 2:9.1.0016-1ubuntu7.18 Ubuntu 22.04 LTS vim 2:8.2.3995-1ubuntu2.34 vim-athena 2:8.2.3995-1ubuntu2.34 vim-common 2:8.2.3995-1ubuntu2.34 vim-gtk 2:8.2.3995-1ubuntu2.34 vim-gtk3 2:8.2.3995-1ubuntu2.34 vim-gui-common 2:8.2.3995-1ubuntu2.34 vim-nox 2:8.2.3995-1ubuntu2.34 vim-runtime 2:8.2.3995-1ubuntu2.34 vim-tiny 2:8.2.3995-1ubuntu2.34 xxd 2:8.2.3995-1ubuntu2.34 Ubuntu 20.04 LTS vim 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-athena 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-common 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-gtk 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-gtk3 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-gui-common 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-nox 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-runtime 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-tiny 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro xxd 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro Ubuntu 18.04 LTS vim 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-athena 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-common 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gnome 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gtk 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gtk3 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gui-common 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-nox 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-runtime 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-tiny 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro xxd 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro Ubuntu 16.04 LTS vim 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-athena 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-athena-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-common 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gnome 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gnome-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk3 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk3-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gui-common 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-nox 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-nox-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-runtime 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-tiny 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro Ubuntu 14.04 LTS vim 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-athena 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-common 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-gnome 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-gtk 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-gui-common 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-lesstif 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-nox 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-runtime 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-tiny 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8541-1 CVE-2026-59856, CVE-2026-59857, CVE-2026-59858 Package Information: https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubuntu4.7 https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.18 https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.34 . Security issues in Vim were addressed in Ubuntu updates, ensuring user protection from command execution risks.. Ubuntu updates,Vim security issues,Patch management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 14, 2026 Important Ubuntu
217

Oracle Linux 9 ELSA-2026-38511 vim Important Code Injection

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-38511 http://linux.oracle.com/errata/ELSA-2026-38511.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-26.0.1.el9_8.10.x86_64.rpm vim-common-8.2.2637-26.0.1.el9_8.10.x86_64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.10.x86_64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.10.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.10.x86_64.rpm aarch64: vim-X11-8.2.2637-26.0.1.el9_8.10.aarch64.rpm vim-common-8.2.2637-26.0.1.el9_8.10.aarch64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.10.aarch64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.10.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.10.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-26.0.1.el9_8.10.src.rpm Related CVEs: CVE-2026-46483 CVE-2026-47162 CVE-2026-47167 CVE-2026-52858 Description of changes: [8.2.2637-26.0.1.el9_8.10] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.10] - RHEL-186659 CVE-2026-47162 vim: code injection via NetrwBookHistSave() [2:8.2.2637-26.9] - RHEL-186646 CVE-2026-52858 vim: possible code execution with python3complete [2:8.2.2637-26.8] - RHEL-185874 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin [2:8.2.2637-26.7] - RHEL-178243 CVE-2026-46483 vim: command injection in tar plugin [2:8.2.2637-26.6] - CVE-2026-41411 vim: Command injection via backticks in tag files [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata .Important security advisory for Oracle Linux 9 addressing critical code injection issues in vim and providing vital updates.. Oracle Linux Security, vim Security Update, Important Advisory, Code Injection Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 14, 2026 Important Oracle
217

Oracle Linux 9 Vim Moderate Arbitrary File Overwrite Vuln ELSA-2026-22717

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-22717 http://linux.oracle.com/errata/ELSA-2026-22717.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-common-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.5.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.5.x86_64.rpm aarch64: vim-X11-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-common-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.5.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-26.0.1.el9_8.5.src.rpm Related CVEs: CVE-2026-35177 Description of changes: [8.2.2637-26.0.1.el9_8.5] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags [2:8.2.2637-26.1] - RHEL-159630 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 9 updates for vim address medium severity issues including file overwrite vulnerabilities. Install now!. Oracle Linux Vim Security Update, File Overwrite Vulnerability Fix, Oracle Security Advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate Oracle
217

Oracle Linux 9 Vim Moderate Command Injection Vuln ELSA-2026-28209

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28209 http://linux.oracle.com/errata/ELSA-2026-28209.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-26.0.1.el9_8.6.x86_64.rpm vim-common-8.2.2637-26.0.1.el9_8.6.x86_64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.6.x86_64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.6.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.6.x86_64.rpm aarch64: vim-X11-8.2.2637-26.0.1.el9_8.6.aarch64.rpm vim-common-8.2.2637-26.0.1.el9_8.6.aarch64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.6.aarch64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.6.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-26.0.1.el9_8.6.src.rpm Related CVEs: CVE-2026-41411 Description of changes: [8.2.2637-26.0.1.el9_8.6] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.6] - CVE-2026-41411 vim: Command injection via backticks in tag files [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags [2:8.2.2637-26.1] - RHEL-159630 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Advisory ELSA-2026-28209 addresses moderate command injection issues in Vim.. Oracle Linux Update, Vim Command Injection, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 Important Oracle
219

Rocky Linux 8 vim Moderate Command Injection Vuln RLSA-2026-28553

Moderate: vim security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28553", "synopsis": "Moderate: vim security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for vim.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Vim (Vi IMproved) is an updated and improved version of the vi editor.\n\nSecurity Fix(es):\n\n* vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2461614", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2461614", "description": ""}], "cves": [{"name": "CVE-2026-41411", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41411", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.3", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-06-25T06:00:21.063779Z", "rpms": {"Rocky Linux 8": {"nvras": ["vim-2:8.0.1763-24.el8_10.src.rpm", "vim-common-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-common-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-common-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-common-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-debugsource-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-debugsource-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-enhanced-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-enhanced-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm","vim-filesystem-2:8.0.1763-24.el8_10.noarch.rpm", "vim-minimal-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-minimal-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-minimal-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-minimal-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-X11-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-X11-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-X11-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-X11-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Ensure your Rocky Linux system is secure with the latest vim update, addressing command injection risks effectively.. Rocky Linux security update, vim command injection, remote code execution, Linux security patch, software vulnerabilities. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 25, 2026 moderate Rocky Linux
217

Oracle Linux 8 vim Moderate Command Injection Vulnerability ELSA-2026-28553

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28553 http://linux.oracle.com/errata/ELSA-2026-28553.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.0.1763-24.0.1.el8_10.x86_64.rpm vim-common-8.0.1763-24.0.1.el8_10.x86_64.rpm vim-enhanced-8.0.1763-24.0.1.el8_10.x86_64.rpm vim-filesystem-8.0.1763-24.0.1.el8_10.noarch.rpm vim-minimal-8.0.1763-24.0.1.el8_10.x86_64.rpm aarch64: vim-X11-8.0.1763-24.0.1.el8_10.aarch64.rpm vim-common-8.0.1763-24.0.1.el8_10.aarch64.rpm vim-enhanced-8.0.1763-24.0.1.el8_10.aarch64.rpm vim-filesystem-8.0.1763-24.0.1.el8_10.noarch.rpm vim-minimal-8.0.1763-24.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/vim-8.0.1763-24.0.1.el8_10.src.rpm Related CVEs: CVE-2026-41411 Description of changes: [8.0.1763-24.0.1] - Remove upstream references [Orabug: 31197557] - Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984] [2:8.0.1763-24] - CVE-2026-41411 vim: Command injection via backticks in tag files _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 updates address command injection risks in vim packages ensuring system security and performance.. Oracle Linux 8 vim update command injection. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2026 Important Oracle
219

Rocky Linux 10 RLSA-2026-28210 vim Moderate Command Injection

Moderate: vim security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28210", "synopsis": "Moderate: vim security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for vim.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Vim (Vi IMproved) is an updated and improved version of the vi editor.\n\nSecurity Fix(es):\n\n* vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2461614", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2461614", "description": ""}], "cves": [{"name": "CVE-2026-41411", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41411", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.3", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-06-24T12:05:09.232192Z", "rpms": {"Rocky Linux 10": {"nvras": ["xxd-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-X11-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-X11-2:9.1.083-9.el10_2.4.ppc64le.rpm", "xxd-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-data-2:9.1.083-9.el10_2.4.noarch.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "xxd-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm","vim-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.s390x.rpm", "xxd-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.ppc64le.rpm", "xxd-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "xxd-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.aarch64.rpm", "xxd-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-X11-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "xxd-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-2:9.1.083-9.el10_2.4.src.rpm", "vim-X11-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-filesystem-2:9.1.083-9.el10_2.4.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate security update for vim in Rocky Linux addresses critical command injection issues ensuring stability and security.. Rocky Linux update, Vim security fix, command injection patch, moderate severity advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 24, 2026 moderate Rocky Linux
172

Ubuntu Vim Critical Code Execution Denial of Service USN-8451-1

Several security issues were fixed in Vim.. ========================================================================== Ubuntu Security Notice USN-8451-1 June 18, 2026 vim vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Vim. Software Description: - vim: Vi IMproved - enhanced vi editor Details: Srinivas Piskala Ganesh Babu discovered that Vim incorrectly handled directory names when serializing browsed paths to the netrw history file. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-47162) It was discovered that Vim incorrectly handled step-definition patterns in the cucumber filetype plugin. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-47167) It was discovered that Vim incorrectly handled import statements during Python omni-completion. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-52858) Andrej Tomči discovered that Vim incorrectly handled certain terminal screen cells when taking a snapshot, leading to an out-of-bounds read. An attacker could possibly use this issue to cause Vim to crash, resulting in a denial of service. (CVE-2026-52859) David Carliez discovered that Vim incorrectly handled reconstructed function and class definitions during Python omni-completion. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-52860) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS vim 2:9.1.2141-1ubuntu4.5 vim-common 2:9.1.2141-1ubuntu4.5 vim-gtk3 2:9.1.2141-1ubuntu4.5 vim-gui-common 2:9.1.2141-1ubuntu4.5 vim-motif 2:9.1.2141-1ubuntu4.5 vim-nox 2:9.1.2141-1ubuntu4.5 vim-runtime 2:9.1.2141-1ubuntu4.5 vim-tiny 2:9.1.2141-1ubuntu4.5 xxd 2:9.1.2141-1ubuntu4.5 Ubuntu 25.10 vim 2:9.1.0967-1ubuntu6.7 vim-athena 2:9.1.0967-1ubuntu6.7 vim-common 2:9.1.0967-1ubuntu6.7 vim-gtk3 2:9.1.0967-1ubuntu6.7 vim-gui-common 2:9.1.0967-1ubuntu6.7 vim-motif 2:9.1.0967-1ubuntu6.7 vim-nox 2:9.1.0967-1ubuntu6.7 vim-runtime 2:9.1.0967-1ubuntu6.7 vim-tiny 2:9.1.0967-1ubuntu6.7 xxd 2:9.1.0967-1ubuntu6.7 Ubuntu 24.04 LTS vim 2:9.1.0016-1ubuntu7.16 vim-athena 2:9.1.0016-1ubuntu7.16 vim-common 2:9.1.0016-1ubuntu7.16 vim-gtk3 2:9.1.0016-1ubuntu7.16 vim-gui-common 2:9.1.0016-1ubuntu7.16 vim-motif 2:9.1.0016-1ubuntu7.16 vim-nox 2:9.1.0016-1ubuntu7.16 vim-runtime 2:9.1.0016-1ubuntu7.16 vim-tiny 2:9.1.0016-1ubuntu7.16 xxd 2:9.1.0016-1ubuntu7.16 Ubuntu 22.04 LTS vim 2:8.2.3995-1ubuntu2.32 vim-athena 2:8.2.3995-1ubuntu2.32 vim-common 2:8.2.3995-1ubuntu2.32 vim-gtk 2:8.2.3995-1ubuntu2.32 vim-gtk3 2:8.2.3995-1ubuntu2.32 vim-gui-common 2:8.2.3995-1ubuntu2.32 vim-nox 2:8.2.3995-1ubuntu2.32 vim-runtime 2:8.2.3995-1ubuntu2.32 vim-tiny 2:8.2.3995-1ubuntu2.32 xxd 2:8.2.3995-1ubuntu2.32 Ubuntu 20.04 LTS vim 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-athena 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-common 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-gtk 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-gtk3 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-gui-common 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-nox 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-runtime 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-tiny 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro xxd 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro Ubuntu 18.04 LTS vim 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-athena 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-common 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gnome 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gtk 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gtk3 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gui-common 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-nox 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-runtime 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-tiny 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro xxd 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro Ubuntu 16.04 LTS vim 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-athena 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-athena-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-common 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gnome 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gnome-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk3 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk3-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gui-common 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-nox 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-nox-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-runtime 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-tiny 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro Ubuntu 14.04 LTS vim 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-athena 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-common 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-gnome 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-gtk 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-gui-common 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-lesstif 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-nox 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-runtime 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-tiny 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8451-1 CVE-2026-47162, CVE-2026-47167, CVE-2026-52858, CVE-2026-52859, CVE-2026-52860 Package Information: https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubuntu4.5 https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.7 https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.16 https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.32 . Multiple security issues resolved in Vim for Ubuntu LTS releases, addressing arbitrary code execution risks and denial of service.. Vim security issues, Ubuntu patch update, code execution vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 18, 2026 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200