vim-8.2.2637-26.el9_8.21.ML.1

エラータID: AXSA:2026-1861:24

Release date: 
Thursday, September 17, 2026 - 14:29
Subject: 
vim-8.2.2637-26.el9_8.21.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

* vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator (CVE-2026-28420)
* vim: Vim: Denial of Service via out-of-bounds write in terminal handling (CVE-2026-52859)
* vim: Vim: Denial of Service via crafted spell file (CVE-2026-55892)
* vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding (CVE-2026-59857)
* vim: Vim: Arbitrary command execution via crafted vimball (CVE-2026-73076)
* vim: Vim: Heap buffer overflow allows arbitrary code execution (CVE-2026-73072)
* vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries (CVE-2026-73078)
* vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling (CVE-2026-73077)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-28420
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
CVE-2026-52859
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no upper bound, stopping only when it encounters a NUL terminator. When a cell legitimately fills all VTERM_MAX_CHARS_PER_CELL (6) slots — a base character plus five combining marks — the bundled libvterm returns the array without a terminating NUL, so the loop reads past the fixed six-element array and appends the out-of-bounds values to a buffer reserved for only six characters. A program whose output is rendered inside a :terminal window can trigger this with a short byte sequence and no Vim scripting, leading to a crash. This issue has been patched in version 9.2.0565.
CVE-2026-55892
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.
CVE-2026-59857
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.
CVE-2026-73072
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.
CVE-2026-73076
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.
CVE-2026-73077
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.
CVE-2026-73078
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. vim-8.2.2637-26.el9_8.21.ML.1.src.rpm
    MD5: d3c080b18e36af704932efc12f34465b
    SHA-256: 99a0328992666b3a808988a44e1129802fa71590f8487f857348dc5042eaad70
    Size: 12.27 MB

Asianux Server 9 for x86_64
  1. vim-common-8.2.2637-26.el9_8.21.ML.1.x86_64.rpm
    MD5: 11e41d866a03c42028d8bc951cedd469
    SHA-256: da5487a1bf81c95abeb0a50326b7b7b18f3e0e6ee1efd7ad58fc3476f2ca35e7
    Size: 6.98 MB
  2. vim-enhanced-8.2.2637-26.el9_8.21.ML.1.x86_64.rpm
    MD5: b1bf09066518c2a6fda26c167185f98c
    SHA-256: 01f8f86d6be88ae7c86d884386fe97dd0943ef3cc7d10136193e9d4a105cadfd
    Size: 1.75 MB
  3. vim-filesystem-8.2.2637-26.el9_8.21.ML.1.noarch.rpm
    MD5: 0020a0725338b9015a22c90ba491fae5
    SHA-256: 05ead1ba8b395042e85637e76842ebcc14b550c84e348cf41503432916718e27
    Size: 13.20 kB
  4. vim-minimal-8.2.2637-26.el9_8.21.ML.1.x86_64.rpm
    MD5: f555ed21a8d3ff194c5b4011f6ddbe06
    SHA-256: bdd929dda5fdd1b2d272b50c94f56c4c36e07c957d2cd53e796f16e3a2f9d317
    Size: 674.46 kB
  5. vim-X11-8.2.2637-26.el9_8.21.ML.1.x86_64.rpm
    MD5: c8dbbbe2b17904900c386d0a9e3d9f48
    SHA-256: 7e45a2c6b7e26b895c584c0db81736f851afc36d7603572cc3662a4f71e52a56
    Size: 1.91 MB