RHSA-2026:34477: Important: vim security update
Important: vim security update
Other sources
Vim (Vi IMproved) is an updated and improved version of the vi editor.Security Fix(es): vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) vim: command injection when decompressing .tgz archives (CVE-2026-46483) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/vimto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-commonto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-common-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-debugsourceto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-enhancedto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-enhanced-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-filesystemto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-minimalto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
redhat/vim-minimal-debuginfoto a version that resolves this vulnerability.Fixed in 8.0.1763-19.el8_6.6 - Upgrade
Upgrade
vimto a version that resolves this vulnerability.Fixed in updated and improved version of the vi editorPatch Important: vim security update - Compensating control
Apply the Vim security update described in the advisory (includes fixes for CVE-2026-41411, CVE-2026-46483, CVE-2026-35177, and CVE-2026-34982).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:34477?
The severity of RHSA-2026:34477 is high, with a rating of 7.
What vulnerabilities are addressed in RHSA-2026:34477?
RHSA-2026:34477 addresses arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) and arbitrary file overwrite via path traversal bypass (CVE-2026-35177).
How do I fix RHSA-2026:34477?
To fix RHSA-2026:34477, update the vim package to the latest version provided by the Red Hat security update.
What systems are affected by RHSA-2026:34477?
RHSA-2026:34477 affects Red Hat Enterprise Linux for x86_64 and related vim packages.
What are the potential risks of not addressing RHSA-2026:34477?
Not addressing RHSA-2026:34477 could lead to arbitrary command execution and arbitrary file overwrites, compromising system integrity and security.