RLSA-2026:66336
Dashboard / Vulnerabilities / RLSA-2026:66336
RLSA-2026:66336
Summary: Important: vim security update
Details: Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator (CVE-2026-28420) * vim: Vim: Denial of Service via out-of-bounds write in terminal handling (CVE-2026-52859) * vim: Vim: Denial of Service via crafted spell file (CVE-2026-55892) * vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding (CVE-2026-59857) * vim: Vim: Arbitrary command execution via crafted vimball (CVE-2026-73076) * vim: Vim: Heap buffer overflow allows arbitrary code execution (CVE-2026-73072) * vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries (CVE-2026-73078) * vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling (CVE-2026-73077) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://errata.rockylinux.org/RLSA-2026:66336, https://bugzilla.redhat.com/show_bug.cgi?id=2443484, https://bugzilla.redhat.com/show_bug.cgi?id=2487989, https://bugzilla.redhat.com/show_bug.cgi?id=2492975, https://bugzilla.redhat.com/show_bug.cgi?id=2498863, https://bugzilla.redhat.com/show_bug.cgi?id=2514034, https://bugzilla.redhat.com/show_bug.cgi?id=2514037, https://bugzilla.redhat.com/show_bug.cgi?id=2514058, https://bugzilla.redhat.com/show_bug.cgi?id=2514065, https://access.redhat.com/errata/RHSA-2026:66336
Affected packages
Package
Name: vim
Purl: pkg:rpm/rocky-linux/vim?distro=rocky-linux-10&epoch=2
Affected ranges
Type: ECOSYSTEM
Events:
