SB20260921163 - Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION update for vim
Published: September 21, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 13 vulnerabilities.
1) OS command injection (CVE-ID: CVE-2026-28417)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the netrw standard plugin bundled with Vim. A remote attacker can trick the victim into opening a specially crafted scp:// URL and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
2) Heap-based buffer overflow (CVE-ID: CVE-2026-28421)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in swap file recovery logic. A remote attacker can trick the victim into opening a specially crafted swap file, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
3) OS Command Injection (CVE-ID: CVE-2026-34982)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary OS commands.
The vulnerability exists due to improper neutralization of special elements used in an OS command in modeline processing for the complete, guitabtooltip, and printheader options and the mapset() function when opening a crafted file. A remote attacker can deliver a specially crafted file to execute arbitrary OS commands.
User interaction is required to open a crafted file.
4) Path traversal (CVE-ID: CVE-2026-35177)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to overwrite arbitrary files.
The vulnerability exists due to path traversal in zip.vim when processing specially crafted zip archives. A remote attacker can trick the victim into opening a crafted archive and editing a malicious file within it to overwrite arbitrary files.
User interaction is required, and the file is written when the victim attempts to save it using :w.
5) OS Command Injection (CVE-ID: CVE-2026-41411)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary shell commands.
The vulnerability exists due to improper neutralization of special elements used in an os command in tag file processing when resolving tag filenames from a tags file. A remote attacker can place a specially crafted tags file entry containing backtick syntax and trigger tag navigation to execute arbitrary shell commands.
User interaction is required to perform tag navigation such as :tag, Ctrl-], or vim -t after opening Vim in a directory containing a malicious tags file.
6) OS Command Injection (CVE-ID: CVE-2026-46483)
CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary shell commands.
The vulnerability exists due to improper neutralization of special elements in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives via :Vimuntar on Unix-like systems. A remote attacker can supply a crafted archive filename to execute arbitrary shell commands.
User interaction is required to open the crafted file and invoke the non-routine :Vimuntar command, and only Unix-like systems with the tar plugin enabled are vulnerable.
7) Code Injection (CVE-ID: CVE-2026-47162)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in s:NetrwBookHistSave() in the netrw plugin when serializing browsed directory paths to the history file. A remote attacker can create a specially crafted directory name to execute arbitrary code.
User interaction is required to browse the crafted directory with netrw and later open any directory so the history file is sourced. The injected content persists in the history file until the entry is rotated out.
8) Code Injection (CVE-ID: CVE-2026-52858)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to improper control of code generation in python omni-completion in python3complete.vim when processing a crafted Python file during omni-completion. A local user can place a crafted Python file with attacker-controlled import statements and a sibling package in the working directory to execute arbitrary code.
User interaction is required to invoke omni-completion with CTRL-X CTRL-O while editing the crafted Python file, and the issue affects builds with the Python interpreter enabled and filetype plugins active.
9) Eval Injection (CVE-ID: CVE-2026-47167)
CWE-ID: CWE-95 - Eval Injection
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of directives in dynamically evaluated code in s:stepmatch() in the cucumber filetype plugin when processing crafted step-definition regex patterns from repository .rb files during step-jump handling. A remote attacker can place a specially crafted step-definition pattern in an attacker-controlled repository to execute arbitrary code.
Exploitation requires a Vim build with +ruby support and user interaction to invoke a step-jump mapping on a matching feature line.
10) Out-of-bounds write (CVE-ID: CVE-2026-57455)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the single-byte branch of spell_soundfold_sofo() in src/spell.c when processing an over-long word through SOFO sound-folding. A local user can supply a specially crafted over-long word to cause a denial of service.
The vulnerable path is only reached under a non-multibyte 8-bit encoding such as latin1, with spell checking enabled for a language that uses a SOFO sound-folding table.
11) Code Injection (CVE-ID: CVE-2026-57456)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper control of code generation in Python omni-completion docstring handling in runtime/autoload/python3complete.vim and pythoncomplete.vim when processing a hostile Python buffer during omni-completion. A remote attacker can craft a malicious docstring and convince a user to trigger Python omni-completion to execute arbitrary code.
User interaction is required to open or edit a hostile Python buffer and trigger Python omni-completion. Only builds with +python3 or +python support are affected.
12) Out-of-bounds write (CVE-ID: CVE-2026-55693)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the tree_count_words() function in src/spellfile.c when parsing a crafted .spl/.sug spell file pair during spell suggestion loading. A remote attacker can supply a specially crafted spell file pair to cause a denial of service.
User interaction is required: spell checking must be enabled and the user must invoke spell suggestion on a misspelled word.
13) Code Injection (CVE-ID: CVE-2026-59858)
CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements in the C omni-completion script in runtime/autoload/ccomplete.vim when processing type information from a tags entry during omni-completion. A local user can supply a crafted tags entry and trick the victim into invoking C omni-completion on a hostile .c file to execute arbitrary code.
User interaction is required to open a hostile .c file and invoke omni-completion on a structure-member access, and the issue is reachable only when filetype plugins are enabled and a reachable tags file is used.
Remediation
Install update from vendor's website.