Ubuntu Security Notices USN-8342-1 USN-8342-1: Vim vulnerability Publication date 28 May 2026 Overview Vim could be made to run arbitrary programs if it opened a specially crafted file. Releases 20.04 LTS 18.04 LTS 16.04 LTS 14.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages vim - Vi IMproved - enhanced vi editor Details It was discovered that Vim did not properly handle backticks in tag filenames. An attacker could possibly use this issue to execute arbitrary commands. It was discovered that Vim did not properly handle backticks in tag filenames. An attacker could possibly use this issue to execute arbitrary commands. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 20.04 LTS focal vim – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . vim-athena – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . vim-common – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . vim-gtk – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . vim-gtk3 – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . vim-nox – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . vim-runtime – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . vim-tiny – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . xxd – 2:8.1.2269-1ubuntu5.32+esm6 Ubuntu Pro Fix available with Ubuntu Pro . 18.04 LTS bionic vim – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-athena – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-common – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-gnome – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-gtk – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-gtk3 – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-nox – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-runtime – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . vim-tiny – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . xxd – 2:8.0.1453-1ubuntu1.13+esm18 Ubuntu Pro Fix available with Ubuntu Pro . 16.04 LTS xenial vim – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-athena – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-athena-py2 – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-common – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gnome – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gnome-py2 – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gtk – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gtk-py2 – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gtk3 – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gtk3-py2 – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-nox – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-nox-py2 – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-runtime – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-tiny – 2:7.4.1689-3ubuntu1.5+esm33 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. 14.04 LTS trusty vim – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-athena – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-common – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gnome – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-gtk – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-lesstif – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-nox – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-runtime – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. vim-tiny – 2:7.4.052-1ubuntu3.1+esm27 Ubuntu Pro Fix available with Ubuntu Pro via Legacy Support add-on. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-41411 CVE-2026-41411 Related notices USN-8246-1 USN-8246-1
A vulnerability (CVE-2026-41411, CVSS 6.6 MEDIUM) in Vim allows arbitrary command execution when processing a specially crafted file containing backticks in tag filenames. The flaw affects Vim versions prior to 9.2.0357, and the remediation is to upgrade to Vim version 9.2.0357.