Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:34477: Important: vim security update

This Red Hat security advisory addresses four vulnerabilities in Vim, including arbitrary command execution via a modeline sandbox bypass (CVE-2026-34982, CVSS 8.2 HIGH), arbitrary file overwrite via path traversal in the zip.vim plugin (CVE-2026-35177, CVSS 4.1 MEDIUM), and command injection via malicious tag files (CVE-2026-41411, CVSS 6.6 MEDIUM). The affected versions are Vim prior to 9.2.0276, 9.2.0280, and 9.2.0357, respectively. Red Hat has released patched packages for its supported Enterprise Linux 8.6 streams, and users should apply the update referenced in the advisory.
Read Full Article →

Red Hat Product Errata RHSA-2026:34477 - Security Advisory Issued: 2026-07-01 Updated: 2026-07-01 RHSA-2026:34477 - Security Advisory Overview Updated Packages Synopsis Important: vim security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for vim is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) vim: command injection when decompressing .tgz archives (CVE-2026-46483) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2455400 - CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass BZ - 2455542 - CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass BZ - 2461614 - CVE-2026-41411 vim: Vim: Command injection allows arbitrary code execution via malicious tag files BZ - 2477915 - CVE-2026-46483 vim: command injection when decompressing .tgz archives CVEs CVE-2026-34982 CVE-2026-35177 CVE-2026-41411 CVE-2026-46483 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 SRPM vim-8.0.1763-19.el8_6.6.src.rpm SHA-256: 74c570b37377f4eda3acbc1f1e267e2e34d2bd3b5e75e642563c369062741c82 x86_64 vim-X11-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 8752bb90fcdb3056c6f5f27b8a0ac374f2502bff6b63ae97966c59cf9e10a66b vim-X11-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 90c6e1886a7ad6452916708f0dc0322530ffdf9bbb94b40caea3ed78e24b55c3 vim-X11-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 90c6e1886a7ad6452916708f0dc0322530ffdf9bbb94b40caea3ed78e24b55c3 vim-common-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 586a6527dd8d6753ae86b5a312dbcd89a0bc486701ac4c646e134166f4d6bbe3 vim-common-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 48c34cb3c55d7939958ff4c0da10445c9e19cd1a19bb64ca49aaf3195da8eb94 vim-common-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 48c34cb3c55d7939958ff4c0da10445c9e19cd1a19bb64ca49aaf3195da8eb94 vim-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: e3a2dcdc131668d699a887c41cab3820cbd4635374eaf8d999dd3d4d22bb5ba2 vim-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: e3a2dcdc131668d699a887c41cab3820cbd4635374eaf8d999dd3d4d22bb5ba2 vim-debugsource-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 9700fee68fb6b8bde6f5ce78bd1a9a3369979a71b34a27a746105a634afb03ca vim-debugsource-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 9700fee68fb6b8bde6f5ce78bd1a9a3369979a71b34a27a746105a634afb03ca vim-enhanced-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: d0747e643a930e7738d04288be9cdacd61814c0620fb9b313d73c28345bcaece vim-enhanced-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: f54cbec7acdd11868a1297933c5100a09393509cbbcd5076c9527db73690c6c3 vim-enhanced-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: f54cbec7acdd11868a1297933c5100a09393509cbbcd5076c9527db73690c6c3 vim-filesystem-8.0.1763-19.el8_6.6.noarch.rpm SHA-256: 45373f03f1bfe9062e41894ae4d1d5e896a436dd5377b79b9edd68d67c654b58 vim-minimal-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 9317face07d1c326382eccf224732c05acc445f3ab61e33a028e056e8dad8087 vim-minimal-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 905fdeb9d5cfcc32951e562cdaf50233cf49c2cb74a562ab6250e2edebcbeae9 vim-minimal-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 905fdeb9d5cfcc32951e562cdaf50233cf49c2cb74a562ab6250e2edebcbeae9 Red Hat Enterprise Linux Server - AUS 8.6 SRPM vim-8.0.1763-19.el8_6.6.src.rpm SHA-256: 74c570b37377f4eda3acbc1f1e267e2e34d2bd3b5e75e642563c369062741c82 x86_64 vim-X11-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 8752bb90fcdb3056c6f5f27b8a0ac374f2502bff6b63ae97966c59cf9e10a66b vim-X11-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 90c6e1886a7ad6452916708f0dc0322530ffdf9bbb94b40caea3ed78e24b55c3 vim-X11-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 90c6e1886a7ad6452916708f0dc0322530ffdf9bbb94b40caea3ed78e24b55c3 vim-common-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 586a6527dd8d6753ae86b5a312dbcd89a0bc486701ac4c646e134166f4d6bbe3 vim-common-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 48c34cb3c55d7939958ff4c0da10445c9e19cd1a19bb64ca49aaf3195da8eb94 vim-common-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 48c34cb3c55d7939958ff4c0da10445c9e19cd1a19bb64ca49aaf3195da8eb94 vim-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: e3a2dcdc131668d699a887c41cab3820cbd4635374eaf8d999dd3d4d22bb5ba2 vim-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: e3a2dcdc131668d699a887c41cab3820cbd4635374eaf8d999dd3d4d22bb5ba2 vim-debugsource-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 9700fee68fb6b8bde6f5ce78bd1a9a3369979a71b34a27a746105a634afb03ca vim-debugsource-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 9700fee68fb6b8bde6f5ce78bd1a9a3369979a71b34a27a746105a634afb03ca vim-enhanced-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: d0747e643a930e7738d04288be9cdacd61814c0620fb9b313d73c28345bcaece vim-enhanced-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: f54cbec7acdd11868a1297933c5100a09393509cbbcd5076c9527db73690c6c3 vim-enhanced-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: f54cbec7acdd11868a1297933c5100a09393509cbbcd5076c9527db73690c6c3 vim-filesystem-8.0.1763-19.el8_6.6.noarch.rpm SHA-256: 45373f03f1bfe9062e41894ae4d1d5e896a436dd5377b79b9edd68d67c654b58 vim-minimal-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 9317face07d1c326382eccf224732c05acc445f3ab61e33a028e056e8dad8087 vim-minimal-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 905fdeb9d5cfcc32951e562cdaf50233cf49c2cb74a562ab6250e2edebcbeae9 vim-minimal-debuginfo-8.0.1763-19.el8_6.6.x86_64.rpm SHA-256: 905fdeb9d5cfcc32951e562cdaf50233cf49c2cb74a562ab6250e2edebcbeae9 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article