Red Hat Product Errata RHSA-2026:47982 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:47982 - Security Advisory Overview Updated Packages Synopsis Important: vim security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for vim is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693) vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion (CVE-2026-59856) vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2492968 - CVE-2026-57455 vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() BZ - 2492972 - CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion BZ - 2492980 - CVE-2026-55693 vim: Vim: Out-of-bounds Write in Spell File Word Count BZ - 2498867 - CVE-2026-59856 vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion BZ - 2498868 - CVE-2026-59858 vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion CVEs CVE-2026-55693 CVE-2026-57455 CVE-2026-57456 CVE-2026-59856 CVE-2026-59858 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM vim-8.2.2637-26.el9_8.13.src.rpm SHA-256: c35d0483fd594ed202397aafa4b97e8321ba99d8d2386e1b5bff53e23b046d95 x86_64 vim-X11-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 58572495e2e61808e8318f0a64708650436ada2a477a7b344156a6b948728962 vim-X11-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 9b91fe078851ce176ba5e4221a039e21323393efb229b25fe98f782b5d4dca5f vim-X11-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 9b91fe078851ce176ba5e4221a039e21323393efb229b25fe98f782b5d4dca5f vim-common-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 7be3f4965708eb1ca818caca82df4e039d0cd1a8aa5ebaf1dff1d9e5953d7591 vim-common-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 877a19166aad558170c5f1cad8f68ed06ddde6f4f466a4f1ebd0b68392eac0b9 vim-common-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 877a19166aad558170c5f1cad8f68ed06ddde6f4f466a4f1ebd0b68392eac0b9 vim-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 97aae776d9b78cf19d07f4020b9daa62fa1bdea6702f0f383a93cd11d5d69a2a vim-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 97aae776d9b78cf19d07f4020b9daa62fa1bdea6702f0f383a93cd11d5d69a2a vim-debugsource-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 263e36f2ea2d356f09a5c899ab3f6ef3ba19b235b01dbe47e7de3c6ae50c430b vim-debugsource-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 263e36f2ea2d356f09a5c899ab3f6ef3ba19b235b01dbe47e7de3c6ae50c430b vim-enhanced-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 8e053d9907f42091cab63151e979b7143c2ed3f765b11a343770ced84fb9b17f vim-enhanced-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 2ab4311986e5fb9e6a5a94957ed638558595b6b12f82aecb4eae3ce57591e3af vim-enhanced-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 2ab4311986e5fb9e6a5a94957ed638558595b6b12f82aecb4eae3ce57591e3af vim-filesystem-8.2.2637-26.el9_8.13.noarch.rpm SHA-256: 7758bbb54a85bb53aecdbb9c740c4981b2b42cac6df9580414838c6bdbab8dbd vim-minimal-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: e0ce0717738af870181a9f42589ea54e739a31a96e85e7feb8335e48abba56fd vim-minimal-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 22eacf37c7cc7448990104a4212a1302a54fb25a912e70e3e79246785ae358d1 vim-minimal-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 22eacf37c7cc7448990104a4212a1302a54fb25a912e70e3e79246785ae358d1 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM vim-8.2.2637-26.el9_8.13.src.rpm SHA-256: c35d0483fd594ed202397aafa4b97e8321ba99d8d2386e1b5bff53e23b046d95 x86_64 vim-X11-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 58572495e2e61808e8318f0a64708650436ada2a477a7b344156a6b948728962 vim-X11-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 9b91fe078851ce176ba5e4221a039e21323393efb229b25fe98f782b5d4dca5f vim-X11-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 9b91fe078851ce176ba5e4221a039e21323393efb229b25fe98f782b5d4dca5f vim-common-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 7be3f4965708eb1ca818caca82df4e039d0cd1a8aa5ebaf1dff1d9e5953d7591 vim-common-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 877a19166aad558170c5f1cad8f68ed06ddde6f4f466a4f1ebd0b68392eac0b9 vim-common-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 877a19166aad558170c5f1cad8f68ed06ddde6f4f466a4f1ebd0b68392eac0b9 vim-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 97aae776d9b78cf19d07f4020b9daa62fa1bdea6702f0f383a93cd11d5d69a2a vim-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 97aae776d9b78cf19d07f4020b9daa62fa1bdea6702f0f383a93cd11d5d69a2a vim-debugsource-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 263e36f2ea2d356f09a5c899ab3f6ef3ba19b235b01dbe47e7de3c6ae50c430b vim-debugsource-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 263e36f2ea2d356f09a5c899ab3f6ef3ba19b235b01dbe47e7de3c6ae50c430b vim-enhanced-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 8e053d9907f42091cab63151e979b7143c2ed3f765b11a343770ced84fb9b17f vim-enhanced-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 2ab4311986e5fb9e6a5a94957ed638558595b6b12f82aecb4eae3ce57591e3af vim-enhanced-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 2ab4311986e5fb9e6a5a94957ed638558595b6b12f82aecb4eae3ce57591e3af vim-filesystem-8.2.2637-26.el9_8.13.noarch.rpm SHA-256: 7758bbb54a85bb53aecdbb9c740c4981b2b42cac6df9580414838c6bdbab8dbd vim-minimal-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: e0ce0717738af870181a9f42589ea54e739a31a96e85e7feb8335e48abba56fd vim-minimal-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 22eacf37c7cc7448990104a4212a1302a54fb25a912e70e3e79246785ae358d1 vim-minimal-debuginfo-8.2.2637-26.el9_8.13.x86_64.rpm SHA-256: 22eacf37c7cc7448990104a4212a1302a54fb25a912e70e3e79246785ae358d1 Red Hat Enterprise Linux for IBM z Systems 9 SRPM vim-8.2.2637-26.el9_8.13.src.rpm SHA-256: c35d0483fd594ed202397aafa4b97e8321ba99d8d2386e1b5bff53e23b046d95 s390x vim-X11-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 4d2342e24b0988deba2c581811cbd07324c1cb11f8f271559986b790d8f5ebed vim-X11-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: c6945036b629ee6337bb825a648a161cdce970b0f96ef58b8a30f3ecdbb7ce0d vim-X11-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: c6945036b629ee6337bb825a648a161cdce970b0f96ef58b8a30f3ecdbb7ce0d vim-common-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 879008eb464ca379c704680717f6c29306e7e157d14133f0ed8f3b425d4a4f0b vim-common-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 636ce4e40c3908a338647f0a905451f7468bf155f69f7b519f135a8e05ad2462 vim-common-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 636ce4e40c3908a338647f0a905451f7468bf155f69f7b519f135a8e05ad2462 vim-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 2bc971e404d907173d5aa014bb00a51a20b63fce024f3f18659eee3481f0a275 vim-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 2bc971e404d907173d5aa014bb00a51a20b63fce024f3f18659eee3481f0a275 vim-debugsource-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 44909fa400d72fded9c678c3718134c0dc24d76cfd8688d6bd0eda9de10a9a7c vim-debugsource-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 44909fa400d72fded9c678c3718134c0dc24d76cfd8688d6bd0eda9de10a9a7c vim-enhanced-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 3f008368cd8fb772d14907731c16bb066201fe20048d7e1c7a11b55f74eb0257 vim-enhanced-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 1e571a5d2c44c9f7741d441b9ad81605334948e36f4e8505bee40a21f31568e9 vim-enhanced-debuginfo-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: 1e571a5d2c44c9f7741d441b9ad81605334948e36f4e8505bee40a21f31568e9 vim-filesystem-8.2.2637-26.el9_8.13.noarch.rpm SHA-256: 7758bbb54a85bb53aecdbb9c740c4981b2b42cac6df9580414838c6bdbab8dbd vim-minimal-8.2.2637-26.el9_8.13.s390x.rpm SHA-256: c
This security update addresses multiple critical vulnerabilities in Vim, including arbitrary code execution via malicious Python docstrings or PHP files during omni-completion, arbitrary command execution via crafted tags files, and denial of service via out-of-bounds writes. The CVSS 3.1 base score for these vulnerabilities is 7.8 (High). Affected versions are Vim prior to 9.2.0699, with specific fixes introduced in versions 9.2.0653, 9.2.0698, and 9.2.0699.