vim-8.0.1763-27.el8_10.ML.1
エラータID: AXSA:2026-1312:17
Vim (Vi IMproved) is an updated and improved version of the vi editor.
Security Fix(es):
* vim: command injection when decompressing .tgz archives (CVE-2026-46483)
* vim: Vim: Arbitrary Code Execution via crafted directory names (CVE-2026-47162)
* vim: Vim: Arbitrary code execution via Python omni-completion (CVE-2026-52858)
* vim: Vim: Arbitrary code execution via crafted step-definition patterns (CVE-2026-47167)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-46483
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.
CVE-2026-47162
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.
CVE-2026-47167
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping, allowing a crafted pattern in an attacker-controlled repository to execute arbitrary Ruby (and through it arbitrary shell commands) when the user invokes a step-jump mapping ([d, ]d). This issue has been patched in version 9.2.0496.
CVE-2026-52858
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and from statements found in the current buffer through Python's import machinery. Because the buffer's working directory is on sys.path, opening a hostile .py file with a sibling Python package and invoking omni-completion runs that package's top-level code as the editing user. This issue has been patched in version 9.2.0561.
Update packages.
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping, allowing a crafted pattern in an attacker-controlled repository to execute arbitrary Ruby (and through it arbitrary shell commands) when the user invokes a step-jump mapping ([d, ]d). This issue has been patched in version 9.2.0496.
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and from statements found in the current buffer through Python's import machinery. Because the buffer's working directory is on sys.path, opening a hostile .py file with a sibling Python package and invoking omni-completion runs that package's top-level code as the editing user. This issue has been patched in version 9.2.0561.
N/A
SRPMS
- vim-8.0.1763-27.el8_10.ML.1.src.rpm
MD5: dd8c1a4931eb876c07acdd169f5faf55
SHA-256: 599b9e7d9efdeaf92420abaf8fb1a54d6b25fd5ce58cce8b5c9633c38166a063
Size: 10.75 MB
Asianux Server 8 for x86_64
- vim-common-8.0.1763-27.el8_10.ML.1.x86_64.rpm
MD5: 4ceaa5a1994479405969e9ecfcffecee
SHA-256: 88ee2948f808c512ac014def78c5a274c2105dd23c52414ee2645bcfcb0a258c
Size: 6.34 MB - vim-enhanced-8.0.1763-27.el8_10.ML.1.x86_64.rpm
MD5: 3911eceb968fbe54dcc584b93efbe438
SHA-256: 784f3c53b273c7fba00bf983da2dc85f8a53ab3dd3f21e9cb4d7adb5222fbd60
Size: 1.36 MB - vim-filesystem-8.0.1763-27.el8_10.ML.1.noarch.rpm
MD5: cf64edae5879df707ed2f9214ee3ac0a
SHA-256: d04aab30cb1da2078b28fd1112a158d7b68714b27d1d867e665213b733a7ad5d
Size: 51.25 kB - vim-minimal-8.0.1763-27.el8_10.ML.1.x86_64.rpm
MD5: a8c301339b64302c45e230913657f792
SHA-256: 0a68a5dd2b1c73945d148c4dceed3dafb34a196694167a047864978603c456b4
Size: 576.27 kB - vim-X11-8.0.1763-27.el8_10.ML.1.x86_64.rpm
MD5: e38a6173d7d328a3bedece36902643ca
SHA-256: d414c423438cb1ff36316e102060a3e71c9a43c6152cffeaeee1a1a6710fae6c
Size: 1.50 MB