Security News

Cybersecurity news aggregator

🐧
HIGH Vulnerabilities Ubuntu Security

USN-8500-1: Vim vulnerabilities

Multiple vulnerabilities in Vim include a high-severity path traversal in the zip.vim plugin (CVE-2026-35177, CVSS 4.1) and a high-severity flaw in spell file depth tracking (CVE-2026-55693, CVSS 7.8). Affected versions are Vim prior to 9.2.0280 for CVE-2026-35177 and prior to 9.2.0653 for CVE-2026-55693, requiring upgrades to those respective fixed versions.
Read Full Article →

It was discovered that Vim incorrectly handled path traversal in the zip.vim plugin. An attacker could possibly use this issue to overwrite arbitrary files. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-35177) It was discovered that Vim incorrectly handled depth tracking when processing spell files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-55693, CVE-2026-55892) It was discovered that Vim incorrectly handled filename escaping in the netrw plugin. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-55895) It was discovered that Vim incorrectly handled length calculations when opening encrypted files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-57452) Dhruv Vishesh Gupta discovered that Vim incorrectly handled quoting of archive entry names. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-57453) It was discovered that Vim incorrectly handled bounds checking when translating words through a byte map. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-57455) Chenyuan Mi discovered that Vim incorrectly handled docstring escaping during Python omni-completion. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-57456)

Share this article