vim-8.0.1763-31.el8_10.7.ML.1

エラータID: AXSA:2026-1816:23

Release date: 
Monday, September 14, 2026 - 11:45
Subject: 
vim-8.0.1763-31.el8_10.7.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

* vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator (CVE-2026-28420)
* vim: Vim: Denial of Service via out-of-bounds write in terminal handling (CVE-2026-52859)
* vim: Vim: Denial of Service via crafted spell file (CVE-2026-55892)
* vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding (CVE-2026-59857)
* vim: Vim: Arbitrary command execution via crafted vimball (CVE-2026-73076)
* vim: Vim: Heap buffer overflow allows arbitrary code execution (CVE-2026-73072)
* vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries (CVE-2026-73078)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-28420
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
CVE-2026-52859
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus five combining marks — the bundled libvterm returns the array without a terminating NUL, so the loop reads past the fixed six-element array and appends the out-of-bounds values to a buffer reserved for only six characters. A program whose output is rendered inside a :terminal window can trigger this with a short byte sequence and no Vim scripting, leading to a crash. This issue has been patched in version 9.2.0565.
CVE-2026-55892
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.
CVE-2026-59857
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.
CVE-2026-73072
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.
CVE-2026-73076
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.
CVE-2026-73078
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. vim-8.0.1763-31.el8_10.7.ML.1.src.rpm
    MD5: afd3355ae7c79f3fd3892fccf74b9a75
    SHA-256: bd32edbfa208d9b5b508f667f2c8fe87a63fa333a5715ff34fcc72310bff7756
    Size: 10.76 MB

Asianux Server 8 for x86_64
  1. vim-common-8.0.1763-31.el8_10.7.ML.1.x86_64.rpm
    MD5: 2a6333213d8b570c6573a2f67c770980
    SHA-256: dc763e500b0a29b197b40c1fa81fbe120ed9042aa277a7f91e5ad578793cd100
    Size: 6.34 MB
  2. vim-enhanced-8.0.1763-31.el8_10.7.ML.1.x86_64.rpm
    MD5: 618b54716a9dba400b9d30ebe0c5538e
    SHA-256: f4fa70ff9d84583573aabd76993881ddd99ebe63b50c1ac765e0101aaaa05545
    Size: 1.37 MB
  3. vim-filesystem-8.0.1763-31.el8_10.7.ML.1.noarch.rpm
    MD5: fed4b306186bfce46d016001bd6bda58
    SHA-256: 70d08cafa947d483b4d1c23a49a8a4ce6bb09068bfd7c274c04809fe0c8c9d62
    Size: 52.85 kB
  4. vim-minimal-8.0.1763-31.el8_10.7.ML.1.x86_64.rpm
    MD5: 1b1505431abfd367378d4842c9197405
    SHA-256: d49403e5945efc761c51e538c8affe3d2eda3f687fe08e0197bd05f34c85af40
    Size: 577.71 kB
  5. vim-X11-8.0.1763-31.el8_10.7.ML.1.x86_64.rpm
    MD5: 7220a5aa1aaf415b6a8799b0a3fd5fc8
    SHA-256: fe01ffff41c8ee03cf5ba93b65cd46ff2e14758b181ae7acdd3f6deeaf4a400f
    Size: 1.50 MB