RHSA-2026:33453: Important: vim security update
Important: vim security update
Other sources
Vim (Vi IMproved) is an updated and improved version of the vi editor.Security Fix(es): vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) vim: command injection when decompressing .tgz archives (CVE-2026-46483) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/vimto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-commonto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-debugsourceto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-enhancedto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-enhanced-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-filesystemto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-minimalto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
redhat/vim-minimal-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-15.el8_4.2 - Upgrade
Upgrade
vimto a version that resolves this vulnerability.Patch CVE-2026-41411 - Upgrade
Upgrade
vimto a version that resolves this vulnerability.Patch CVE-2026-46483 - Upgrade
Upgrade
vimto a version that resolves this vulnerability.Patch CVE-2026-35177 - Upgrade
Upgrade
vimto a version that resolves this vulnerability.Patch CVE-2026-34982
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:33453?
The severity of RHSA-2026:33453 is rated as high with a score of 7.
What does RHSA-2026:33453 address?
RHSA-2026:33453 addresses a security vulnerability in vim, which can allow unauthorized access or potential exploitation.
How do I fix RHSA-2026:33453?
To fix RHSA-2026:33453, you should apply the latest security update for vim as provided by Red Hat.
Is RHSA-2026:33453 applicable to my system?
RHSA-2026:33453 is applicable to systems running Red Hat Enterprise Linux Server and its Extended Update Support Extension.
When was RHSA-2026:33453 published?
RHSA-2026:33453 was published on June 30, 2026.