Explore top 10 tips to secure your open-source projects now. Read More
×Several security issues were fixed in Vim.. ========================================================================== Ubuntu Security Notice USN-8541-1 July 14, 2026 vim vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Vim. Software Description: - vim: Vi IMproved - enhanced vi editor Details: Hirohito Higashi discovered that Vim incorrectly escaped class or trait names when performing PHP omni-completion. An attacker could possibly use this issue to trick a user into opening a specially crafted PHP file and executing arbitrary commands. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59856) Hirohito Higashi discovered that Vim incorrectly handled sound-folding of certain words when using a spell file. An attacker could possibly use this issue to cause Vim to crash, resulting in a denial of service. (CVE-2026-59857) It was discovered that Vim incorrectly escaped certain tags file fields when performing C omni-completion. An attacker could possibly use this issue to trick a user into opening a specially crafted file and executing arbitrary commands. (CVE-2026-59858) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS vim 2:9.1.2141-1ubuntu4.7 vim-common 2:9.1.2141-1ubuntu4.7 vim-gtk3 2:9.1.2141-1ubuntu4.7 vim-gui-common 2:9.1.2141-1ubuntu4.7 vim-motif 2:9.1.2141-1ubuntu4.7 vim-nox 2:9.1.2141-1ubuntu4.7 vim-runtime 2:9.1.2141-1ubuntu4.7 vim-tiny 2:9.1.2141-1ubuntu4.7 xxd 2:9.1.2141-1ubuntu4.7 Ubuntu 24.04 LTS vim 2:9.1.0016-1ubuntu7.18 vim-athena 2:9.1.0016-1ubuntu7.18 vim-common 2:9.1.0016-1ubuntu7.18 vim-gtk3 2:9.1.0016-1ubuntu7.18 vim-gui-common 2:9.1.0016-1ubuntu7.18 vim-motif 2:9.1.0016-1ubuntu7.18 vim-nox 2:9.1.0016-1ubuntu7.18 vim-runtime 2:9.1.0016-1ubuntu7.18 vim-tiny 2:9.1.0016-1ubuntu7.18 xxd 2:9.1.0016-1ubuntu7.18 Ubuntu 22.04 LTS vim 2:8.2.3995-1ubuntu2.34 vim-athena 2:8.2.3995-1ubuntu2.34 vim-common 2:8.2.3995-1ubuntu2.34 vim-gtk 2:8.2.3995-1ubuntu2.34 vim-gtk3 2:8.2.3995-1ubuntu2.34 vim-gui-common 2:8.2.3995-1ubuntu2.34 vim-nox 2:8.2.3995-1ubuntu2.34 vim-runtime 2:8.2.3995-1ubuntu2.34 vim-tiny 2:8.2.3995-1ubuntu2.34 xxd 2:8.2.3995-1ubuntu2.34 Ubuntu 20.04 LTS vim 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-athena 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-common 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-gtk 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-gtk3 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-gui-common 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-nox 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-runtime 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro vim-tiny 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro xxd 2:8.1.2269-1ubuntu5.32+esm10 Available with Ubuntu Pro Ubuntu 18.04 LTS vim 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-athena 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-common 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gnome 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gtk 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gtk3 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-gui-common 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-nox 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-runtime 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro vim-tiny 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro xxd 2:8.0.1453-1ubuntu1.13+esm22 Available with Ubuntu Pro Ubuntu 16.04 LTS vim 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-athena 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-athena-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-common 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gnome 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gnome-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk3 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gtk3-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-gui-common 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-nox 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-nox-py2 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-runtime 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro vim-tiny 2:7.4.1689-3ubuntu1.5+esm37 Available with Ubuntu Pro Ubuntu 14.04 LTS vim 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-athena 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-common 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-gnome 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-gtk 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-gui-common 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-lesstif 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-nox 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-runtime 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro vim-tiny 2:7.4.052-1ubuntu3.1+esm31 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8541-1 CVE-2026-59856, CVE-2026-59857, CVE-2026-59858 Package Information: https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubuntu4.7 https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.18 https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.34 . Security issues in Vim were addressed in Ubuntu updates, ensuring user protection from command execution risks.. Ubuntu updates,Vim security issues,Patch management. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-38511 http://linux.oracle.com/errata/ELSA-2026-38511.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-26.0.1.el9_8.10.x86_64.rpm vim-common-8.2.2637-26.0.1.el9_8.10.x86_64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.10.x86_64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.10.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.10.x86_64.rpm aarch64: vim-X11-8.2.2637-26.0.1.el9_8.10.aarch64.rpm vim-common-8.2.2637-26.0.1.el9_8.10.aarch64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.10.aarch64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.10.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.10.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-26.0.1.el9_8.10.src.rpm Related CVEs: CVE-2026-46483 CVE-2026-47162 CVE-2026-47167 CVE-2026-52858 Description of changes: [8.2.2637-26.0.1.el9_8.10] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.10] - RHEL-186659 CVE-2026-47162 vim: code injection via NetrwBookHistSave() [2:8.2.2637-26.9] - RHEL-186646 CVE-2026-52858 vim: possible code execution with python3complete [2:8.2.2637-26.8] - RHEL-185874 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin [2:8.2.2637-26.7] - RHEL-178243 CVE-2026-46483 vim: command injection in tar plugin [2:8.2.2637-26.6] - CVE-2026-41411 vim: Command injection via backticks in tag files [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-22717 http://linux.oracle.com/errata/ELSA-2026-22717.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-common-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.5.x86_64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.5.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.5.x86_64.rpm aarch64: vim-X11-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-common-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.5.aarch64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.5.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-26.0.1.el9_8.5.src.rpm Related CVEs: CVE-2026-35177 Description of changes: [8.2.2637-26.0.1.el9_8.5] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags [2:8.2.2637-26.1] - RHEL-159630 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28209 http://linux.oracle.com/errata/ELSA-2026-28209.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.2.2637-26.0.1.el9_8.6.x86_64.rpm vim-common-8.2.2637-26.0.1.el9_8.6.x86_64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.6.x86_64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.6.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.6.x86_64.rpm aarch64: vim-X11-8.2.2637-26.0.1.el9_8.6.aarch64.rpm vim-common-8.2.2637-26.0.1.el9_8.6.aarch64.rpm vim-enhanced-8.2.2637-26.0.1.el9_8.6.aarch64.rpm vim-filesystem-8.2.2637-26.0.1.el9_8.6.noarch.rpm vim-minimal-8.2.2637-26.0.1.el9_8.6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/vim-8.2.2637-26.0.1.el9_8.6.src.rpm Related CVEs: CVE-2026-41411 Description of changes: [8.2.2637-26.0.1.el9_8.6] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.6] - CVE-2026-41411 vim: Command injection via backticks in tag files [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags [2:8.2.2637-26.1] - RHEL-159630 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function _______________________________________________ El-errata mailing list
Moderate: vim security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28553", "synopsis": "Moderate: vim security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for vim.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Vim (Vi IMproved) is an updated and improved version of the vi editor.\n\nSecurity Fix(es):\n\n* vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2461614", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2461614", "description": ""}], "cves": [{"name": "CVE-2026-41411", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41411", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.3", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-06-25T06:00:21.063779Z", "rpms": {"Rocky Linux 8": {"nvras": ["vim-2:8.0.1763-24.el8_10.src.rpm", "vim-common-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-common-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-common-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-common-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-debugsource-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-debugsource-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-enhanced-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-enhanced-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm","vim-filesystem-2:8.0.1763-24.el8_10.noarch.rpm", "vim-minimal-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-minimal-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-minimal-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-minimal-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-X11-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-X11-2:8.0.1763-24.el8_10.x86_64.rpm", "vim-X11-debuginfo-2:8.0.1763-24.el8_10.aarch64.rpm", "vim-X11-debuginfo-2:8.0.1763-24.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Ensure your Rocky Linux system is secure with the latest vim update, addressing command injection risks effectively.. Rocky Linux security update, vim command injection, remote code execution, Linux security patch, software vulnerabilities. . Severity: moderate. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28553 http://linux.oracle.com/errata/ELSA-2026-28553.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: vim-X11-8.0.1763-24.0.1.el8_10.x86_64.rpm vim-common-8.0.1763-24.0.1.el8_10.x86_64.rpm vim-enhanced-8.0.1763-24.0.1.el8_10.x86_64.rpm vim-filesystem-8.0.1763-24.0.1.el8_10.noarch.rpm vim-minimal-8.0.1763-24.0.1.el8_10.x86_64.rpm aarch64: vim-X11-8.0.1763-24.0.1.el8_10.aarch64.rpm vim-common-8.0.1763-24.0.1.el8_10.aarch64.rpm vim-enhanced-8.0.1763-24.0.1.el8_10.aarch64.rpm vim-filesystem-8.0.1763-24.0.1.el8_10.noarch.rpm vim-minimal-8.0.1763-24.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/vim-8.0.1763-24.0.1.el8_10.src.rpm Related CVEs: CVE-2026-41411 Description of changes: [8.0.1763-24.0.1] - Remove upstream references [Orabug: 31197557] - Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984] [2:8.0.1763-24] - CVE-2026-41411 vim: Command injection via backticks in tag files _______________________________________________ El-errata mailing list
Moderate: vim security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28210", "synopsis": "Moderate: vim security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for vim.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Vim (Vi IMproved) is an updated and improved version of the vi editor.\n\nSecurity Fix(es):\n\n* vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2461614", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2461614", "description": ""}], "cves": [{"name": "CVE-2026-41411", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41411", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.3", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-06-24T12:05:09.232192Z", "rpms": {"Rocky Linux 10": {"nvras": ["xxd-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-X11-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-X11-2:9.1.083-9.el10_2.4.ppc64le.rpm", "xxd-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-data-2:9.1.083-9.el10_2.4.noarch.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "xxd-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm","vim-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.s390x.rpm", "xxd-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.ppc64le.rpm", "xxd-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-minimal-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-enhanced-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "xxd-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-debugsource-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-common-2:9.1.083-9.el10_2.4.aarch64.rpm", "xxd-2:9.1.083-9.el10_2.4.ppc64le.rpm", "vim-X11-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-X11-debuginfo-2:9.1.083-9.el10_2.4.ppc64le.rpm", "xxd-debuginfo-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-2:9.1.083-9.el10_2.4.src.rpm", "vim-X11-2:9.1.083-9.el10_2.4.s390x.rpm", "vim-minimal-2:9.1.083-9.el10_2.4.aarch64.rpm", "vim-enhanced-2:9.1.083-9.el10_2.4.x86_64.rpm", "vim-filesystem-2:9.1.083-9.el10_2.4.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate security update for vim in Rocky Linux addresses critical command injection issues ensuring stability and security.. Rocky Linux update, Vim security fix, command injection patch, moderate severity advisory. . Severity: moderate. LinuxSecurity.com Team
Several security issues were fixed in Vim.. ========================================================================== Ubuntu Security Notice USN-8451-1 June 18, 2026 vim vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Vim. Software Description: - vim: Vi IMproved - enhanced vi editor Details: Srinivas Piskala Ganesh Babu discovered that Vim incorrectly handled directory names when serializing browsed paths to the netrw history file. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-47162) It was discovered that Vim incorrectly handled step-definition patterns in the cucumber filetype plugin. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-47167) It was discovered that Vim incorrectly handled import statements during Python omni-completion. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-52858) Andrej Tomči discovered that Vim incorrectly handled certain terminal screen cells when taking a snapshot, leading to an out-of-bounds read. An attacker could possibly use this issue to cause Vim to crash, resulting in a denial of service. (CVE-2026-52859) David Carliez discovered that Vim incorrectly handled reconstructed function and class definitions during Python omni-completion. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-52860) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS vim 2:9.1.2141-1ubuntu4.5 vim-common 2:9.1.2141-1ubuntu4.5 vim-gtk3 2:9.1.2141-1ubuntu4.5 vim-gui-common 2:9.1.2141-1ubuntu4.5 vim-motif 2:9.1.2141-1ubuntu4.5 vim-nox 2:9.1.2141-1ubuntu4.5 vim-runtime 2:9.1.2141-1ubuntu4.5 vim-tiny 2:9.1.2141-1ubuntu4.5 xxd 2:9.1.2141-1ubuntu4.5 Ubuntu 25.10 vim 2:9.1.0967-1ubuntu6.7 vim-athena 2:9.1.0967-1ubuntu6.7 vim-common 2:9.1.0967-1ubuntu6.7 vim-gtk3 2:9.1.0967-1ubuntu6.7 vim-gui-common 2:9.1.0967-1ubuntu6.7 vim-motif 2:9.1.0967-1ubuntu6.7 vim-nox 2:9.1.0967-1ubuntu6.7 vim-runtime 2:9.1.0967-1ubuntu6.7 vim-tiny 2:9.1.0967-1ubuntu6.7 xxd 2:9.1.0967-1ubuntu6.7 Ubuntu 24.04 LTS vim 2:9.1.0016-1ubuntu7.16 vim-athena 2:9.1.0016-1ubuntu7.16 vim-common 2:9.1.0016-1ubuntu7.16 vim-gtk3 2:9.1.0016-1ubuntu7.16 vim-gui-common 2:9.1.0016-1ubuntu7.16 vim-motif 2:9.1.0016-1ubuntu7.16 vim-nox 2:9.1.0016-1ubuntu7.16 vim-runtime 2:9.1.0016-1ubuntu7.16 vim-tiny 2:9.1.0016-1ubuntu7.16 xxd 2:9.1.0016-1ubuntu7.16 Ubuntu 22.04 LTS vim 2:8.2.3995-1ubuntu2.32 vim-athena 2:8.2.3995-1ubuntu2.32 vim-common 2:8.2.3995-1ubuntu2.32 vim-gtk 2:8.2.3995-1ubuntu2.32 vim-gtk3 2:8.2.3995-1ubuntu2.32 vim-gui-common 2:8.2.3995-1ubuntu2.32 vim-nox 2:8.2.3995-1ubuntu2.32 vim-runtime 2:8.2.3995-1ubuntu2.32 vim-tiny 2:8.2.3995-1ubuntu2.32 xxd 2:8.2.3995-1ubuntu2.32 Ubuntu 20.04 LTS vim 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-athena 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-common 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-gtk 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-gtk3 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-gui-common 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-nox 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-runtime 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro vim-tiny 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro xxd 2:8.1.2269-1ubuntu5.32+esm8 Available with Ubuntu Pro Ubuntu 18.04 LTS vim 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-athena 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-common 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gnome 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gtk 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gtk3 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-gui-common 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-nox 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-runtime 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro vim-tiny 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro xxd 2:8.0.1453-1ubuntu1.13+esm20 Available with Ubuntu Pro Ubuntu 16.04 LTS vim 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-athena 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-athena-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-common 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gnome 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gnome-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk3 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gtk3-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-gui-common 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-nox 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-nox-py2 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-runtime 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro vim-tiny 2:7.4.1689-3ubuntu1.5+esm35 Available with Ubuntu Pro Ubuntu 14.04 LTS vim 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-athena 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-common 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-gnome 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-gtk 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-gui-common 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-lesstif 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-nox 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-runtime 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro vim-tiny 2:7.4.052-1ubuntu3.1+esm29 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8451-1 CVE-2026-47162, CVE-2026-47167, CVE-2026-52858, CVE-2026-52859, CVE-2026-52860 Package Information: https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubuntu4.5 https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.7 https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.16 https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.32 . Multiple security issues resolved in Vim for Ubuntu LTS releases, addressing arbitrary code execution risks and denial of service.. Vim security issues, Ubuntu patch update, code execution vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.