RHSA-2026:55431: Important: vim security update
Vim (Vi IMproved) is an updated and improved version of the vi editor.Security Fix(es): vim: Vim: Arbitrary Code Execution via crafted directory names (CVE-2026-47162) vim: Vim: Arbitrary code execution via Python omni-completion (CVE-2026-52858) vim: Vim: Arbitrary code execution via crafted step-definition patterns (CVE-2026-47167) vim: Vim: Denial of Service via stack out-of-bounds write in spellsoundfoldsofo() (CVE-2026-57455) vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693) vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion (CVE-2026-59856) vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/vimto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-commonto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-datato a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-debugsourceto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-enhancedto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-enhanced-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-filesystemto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-minimalto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-minimal-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/xxdto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/xxd-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4 - Upgrade
Upgrade
redhat/vim-commonto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/vim-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/vim-debugsourceto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/vim-enhancedto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/vim-enhanced-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/vim-minimalto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/vim-minimal-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/xxdto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa - Upgrade
Upgrade
redhat/xxd-debuginfoto a version that resolves this vulnerability.Fixed in 9.1.083-5.el10_0.4.aa