Red Hat Product Errata RHSA-2026:28050 - Security Advisory Issued: 2026-06-22 Updated: 2026-06-22 RHSA-2026:28050 - Security Advisory Overview Updated Packages Synopsis Important: vim security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for vim is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) vim: command injection when decompressing .tgz archives (CVE-2026-46483) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2455400 - CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass BZ - 2455542 - CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass BZ - 2461614 - CVE-2026-41411 vim: Vim: Command injection allows arbitrary code execution via malicious tag files BZ - 2477915 - CVE-2026-46483 vim: command injection when decompressing .tgz archives CVEs CVE-2026-34982 CVE-2026-35177 CVE-2026-41411 CVE-2026-46483 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM vim-8.2.2637-22.el9_6.3.src.rpm SHA-256: 417553b67355c391f03c47e3e6a60c21ad125676d53f166ba90f761b7d71eccd x86_64 vim-X11-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 387ae8736b1d258ed6e17f97392591f0b327ff5c31e73f0ca68b81300c9c932d vim-X11-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c488ff4d5468113842854b25594bea438a3a1082d1c3cf0bbce4011372a89d98 vim-X11-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c488ff4d5468113842854b25594bea438a3a1082d1c3cf0bbce4011372a89d98 vim-common-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 8191288fd1f8147e5507b6ed3563c192c50e3db514d4d3217bd762b93023c7f8 vim-common-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 71aecd711e32ee9a26f537729a0c4cae912b185cabd68eec0c77c50c3fd51edc vim-common-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 71aecd711e32ee9a26f537729a0c4cae912b185cabd68eec0c77c50c3fd51edc vim-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c4767008819d07a4e7fb88b8609b7d81e3972da8d6d6cd116b60838b477540a0 vim-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c4767008819d07a4e7fb88b8609b7d81e3972da8d6d6cd116b60838b477540a0 vim-debugsource-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 0cacd5fbfc04abb40f752fec81984ea6cf180d8a7faac1fb80dc134632c8d112 vim-debugsource-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 0cacd5fbfc04abb40f752fec81984ea6cf180d8a7faac1fb80dc134632c8d112 vim-enhanced-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 460012ee795ebd0d102f9d47c87af4bfac6e95f0c3428b377bf797f2503b7379 vim-enhanced-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 298d750a216cd87f2c0d80d40f98b5a3f439f8fb530ab8e2c7fa193a2c34cc57 vim-enhanced-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 298d750a216cd87f2c0d80d40f98b5a3f439f8fb530ab8e2c7fa193a2c34cc57 vim-filesystem-8.2.2637-22.el9_6.3.noarch.rpm SHA-256: 7a7b563c63cf08a4194f1c685a32d653a62879aea5ef2898f8282bf17bddbba8 vim-minimal-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: b183ebdc70839dc03a9d293033f056d49e50f7d823b11611275b2f1024b57667 vim-minimal-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 3c027d0819b8af3791eba8e1dacd1bcc20be9e6563e4036976a37345a86ca555 vim-minimal-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 3c027d0819b8af3791eba8e1dacd1bcc20be9e6563e4036976a37345a86ca555 Red Hat Enterprise Linux Server - AUS 9.6 SRPM vim-8.2.2637-22.el9_6.3.src.rpm SHA-256: 417553b67355c391f03c47e3e6a60c21ad125676d53f166ba90f761b7d71eccd x86_64 vim-X11-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 387ae8736b1d258ed6e17f97392591f0b327ff5c31e73f0ca68b81300c9c932d vim-X11-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c488ff4d5468113842854b25594bea438a3a1082d1c3cf0bbce4011372a89d98 vim-X11-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c488ff4d5468113842854b25594bea438a3a1082d1c3cf0bbce4011372a89d98 vim-common-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 8191288fd1f8147e5507b6ed3563c192c50e3db514d4d3217bd762b93023c7f8 vim-common-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 71aecd711e32ee9a26f537729a0c4cae912b185cabd68eec0c77c50c3fd51edc vim-common-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 71aecd711e32ee9a26f537729a0c4cae912b185cabd68eec0c77c50c3fd51edc vim-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c4767008819d07a4e7fb88b8609b7d81e3972da8d6d6cd116b60838b477540a0 vim-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: c4767008819d07a4e7fb88b8609b7d81e3972da8d6d6cd116b60838b477540a0 vim-debugsource-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 0cacd5fbfc04abb40f752fec81984ea6cf180d8a7faac1fb80dc134632c8d112 vim-debugsource-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 0cacd5fbfc04abb40f752fec81984ea6cf180d8a7faac1fb80dc134632c8d112 vim-enhanced-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 460012ee795ebd0d102f9d47c87af4bfac6e95f0c3428b377bf797f2503b7379 vim-enhanced-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 298d750a216cd87f2c0d80d40f98b5a3f439f8fb530ab8e2c7fa193a2c34cc57 vim-enhanced-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 298d750a216cd87f2c0d80d40f98b5a3f439f8fb530ab8e2c7fa193a2c34cc57 vim-filesystem-8.2.2637-22.el9_6.3.noarch.rpm SHA-256: 7a7b563c63cf08a4194f1c685a32d653a62879aea5ef2898f8282bf17bddbba8 vim-minimal-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: b183ebdc70839dc03a9d293033f056d49e50f7d823b11611275b2f1024b57667 vim-minimal-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 3c027d0819b8af3791eba8e1dacd1bcc20be9e6563e4036976a37345a86ca555 vim-minimal-debuginfo-8.2.2637-22.el9_6.3.x86_64.rpm SHA-256: 3c027d0819b8af3791eba8e1dacd1bcc20be9e6563e4036976a37345a86ca555 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM vim-8.2.2637-22.el9_6.3.src.rpm SHA-256: 417553b67355c391f03c47e3e6a60c21ad125676d53f166ba90f761b7d71eccd s390x vim-X11-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 726224c6dbe6684e17b7a7a46430103bd4f2616519fe9d080c804fc607d7f200 vim-X11-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 0c28415231800f65bfe9ed5510abf7f86ea43a2aae6e309185bd3a4381aa1430 vim-X11-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 0c28415231800f65bfe9ed5510abf7f86ea43a2aae6e309185bd3a4381aa1430 vim-common-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: b0b7438d946c232e1f2e8a84d0ea47a3f75e7fe3d8efe3f2439cdf8508d93050 vim-common-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 404f5adf5dc8233fe15b7e33a3567b77092f0d73362dd8306400403c7f58f416 vim-common-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 404f5adf5dc8233fe15b7e33a3567b77092f0d73362dd8306400403c7f58f416 vim-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 195c1b2e2ab17f85598280245066881cc5c27b43ff65a14ed3712707b57788d1 vim-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 195c1b2e2ab17f85598280245066881cc5c27b43ff65a14ed3712707b57788d1 vim-debugsource-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 4f1f03cbee7fbc398168411ba4f045d847d61f16ab5d1c3ff8e7b8ae0f461ed2 vim-debugsource-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 4f1f03cbee7fbc398168411ba4f045d847d61f16ab5d1c3ff8e7b8ae0f461ed2 vim-enhanced-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 23d874a357f200c94aa3e3c8c8769e712d3f2ad71a6e0fadf7481aad24082712 vim-enhanced-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: b7455436aa4e5b6391c53720f090014d7ccdf0dd999a18ee45bab5c3177fbc93 vim-enhanced-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: b7455436aa4e5b6391c53720f090014d7ccdf0dd999a18ee45bab5c3177fbc93 vim-filesystem-8.2.2637-22.el9_6.3.noarch.rpm SHA-256: 7a7b563c63cf08a4194f1c685a32d653a62879aea5ef2898f8282bf17bddbba8 vim-minimal-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: adead0a7d3ff5e63bec61183336641bde1722be55f6ae58c5b0501a26ba4cf71 vim-minimal-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 7eb4bec8fd6c9e349076d9a5077c132a8705eddf02d72c6b66f29b4fb755e937 vim-minimal-debuginfo-8.2.2637-22.el9_6.3.s390x.rpm SHA-256: 7eb4bec8fd6c9e349076d9a5077c132a8705eddf02d72c6b66f29b4fb755e937 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRP
This security update addresses four vulnerabilities in Vim, including arbitrary command execution via a modeline sandbox bypass (CVE-2026-34982, CVSS 8.2 HIGH), arbitrary file overwrite via path traversal in the zip.vim plugin (CVE-2026-35177, CVSS 4.1 MEDIUM), command injection via malicious tag files (CVE-2026-41411, CVSS 6.6 MEDIUM), and command injection when decompressing .tgz archives. The affected versions are Vim prior to 9.2.0276, 9.2.0280, and 9.2.0357, respectively. Red Hat has released patched packages for Red Hat Enterprise Linux 9.6 Extended Update Support and related variants.