REDHAT-BUG-2453139: High severity vim Vim vulnerability
Published Mar 30, 2026
·Updated
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking PMLE.
Affected Software
1 affected component
vim Vim<9.2.0272
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vimto a version that resolves this vulnerability.Fixed in 9.2.0272
Event History
Mar 30, 2026
Data Sourced
via Red Hat·07:02 PM
DescriptionSeverityAffected Software