RHSA-2026:6540: Important: vim security update
Published Apr 2, 2026
·Updated
Important: vim security update
Other sources
Vim (Vi IMproved) is an updated and improved version of the vi editor.Security Fix(es): vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749) vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417) vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421) vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
47 affected componentsFixes available
Red Hat Red Hat Enterprise Linux Server - AUS
Red Hat Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux for IBM z Systems - 4 years of updates
Red Hat Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for x86_64 - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for ARM 64 - 4 years of updates
Red Hat Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle
redhat/vim<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-common<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-common-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-debugsource<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-enhanced<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-enhanced-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-filesystem<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-minimal<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-minimal-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-common<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-common-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-debugsource<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-enhanced<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-enhanced-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-minimal<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-minimal-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-common<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-common-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-debugsource<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-enhanced<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-enhanced-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-minimal<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-minimal-debuginfo<8.2.2637-20.el9_4.2
8.2.2637-20.el9_4.2
redhat/vim-common<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
redhat/vim-common-debuginfo<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
redhat/vim-debuginfo<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
redhat/vim-debugsource<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
redhat/vim-enhanced<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
redhat/vim-enhanced-debuginfo<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
redhat/vim-minimal<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
redhat/vim-minimal-debuginfo<8.2.2637-20.el9_4.2.aa
8.2.2637-20.el9_4.2.aa
Remediation
Event History
Apr 2, 2026
Advisory Published
via Red Hat·09:03 PM
Data Sourced
via Red Hat·09:03 PM
DescriptionSeverityAffected Software
Apr 17, 2026
Advisory Published
via Red Hat·10:00 PM
Data Sourced
via Red Hat·10:00 PM
Remedy