ALSA-2026:66366
Dashboard / Vulnerabilities / ALSA-2026:66366
ALSA-2026:66366
Summary: Important: vim security update
Details: Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator (CVE-2026-28420) * vim: Vim: Denial of Service via out-of-bounds write in terminal handling (CVE-2026-52859) * vim: Vim: Denial of Service via crafted spell file (CVE-2026-55892) * vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding (CVE-2026-59857) * vim: Vim: Arbitrary command execution via crafted vimball (CVE-2026-73076) * vim: Vim: Heap buffer overflow allows arbitrary code execution (CVE-2026-73072) * vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries (CVE-2026-73078) * vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling (CVE-2026-73077) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2026:66366, https://access.redhat.com/security/cve/CVE-2026-28420, https://access.redhat.com/security/cve/CVE-2026-52859, https://access.redhat.com/security/cve/CVE-2026-55892, https://access.redhat.com/security/cve/CVE-2026-59857, https://access.redhat.com/security/cve/CVE-2026-73072, https://access.redhat.com/security/cve/CVE-2026-73076, https://access.redhat.com/security/cve/CVE-2026-73077, https://access.redhat.com/security/cve/CVE-2026-73078, https://bugzilla.redhat.com/2443484, https://bugzilla.redhat.com/2487989, https://bugzilla.redhat.com/2492975, https://bugzilla.redhat.com/2498863, https://bugzilla.redhat.com/2514034, https://bugzilla.redhat.com/2514037, https://bugzilla.redhat.com/2514058, https://bugzilla.redhat.com/2514065, https://errata.almalinux.org/9/ALSA-2026-66366.html
Affected packages
Package
Name: vim-X11
Purl: pkg:rpm/almalinux/vim-X11
Affected ranges
Type: ECOSYSTEM
Events:
