Vim bug can run code
vim has a CERT-Bund advisory for 6 vulnerabilities in versions before 9.2.0073. A local attacker can exploit multiple vulnerabilities in vim to execute arbitrary code, cause a denial-of-service condition, or manipulate data.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 9.2.0073Fix recorded today
- Affected versions
- before 9.2.0073
- Affects
- vim+3 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
A local attacker can exploit multiple vulnerabilities in vim to execute arbitrary code, cause a denial-of-service condition, or manipulate data.
What to do
Check your vim version. If it is before 9.2.0073, this advisory applies.
Update vim to 9.2.0073 or newer.
Technical details
Affected software: vim, Sonstiges, UNIX, Windows
A local attacker can exploit multiple vulnerabilities in vim to execute arbitrary code, cause a denial-of-service condition, or manipulate data. The advisory tracks CVE-2026-28417, CVE-2026-28418, CVE-2026-28419, CVE-2026-28420, CVE-2026-28421, CVE-2026-28422. In CERT-Bund's CSAF data, affected versions are before 9.2.0073, before 9.2.0074, before 9.2.0075, before 9.2.0076, and the fixed version is 9.2.0073, 9.2.0074, 9.2.0075, 9.2.0076. Affected operating systems listed by CERT-Bund: Sonstiges, UNIX, Windows.
References
- wid.cert-bund.de · wid-sec-w-2026-0556.json technical description
- seclists.org · 233 third party advisory
- seclists.org · 234 third party advisory
- seclists.org · 235 third party advisory
- seclists.org · 236 third party advisory
- seclists.org · 237 third party advisory
- seclists.org · 238 third party advisory
- bugzilla.redhat.com · show_bug.cgi third party advisory
- bugzilla.redhat.com · show_bug.cgi third party advisory
- bugzilla.redhat.com · show_bug.cgi third party advisory
- bugzilla.redhat.com · show_bug.cgi third party advisory
- bugzilla.redhat.com · show_bug.cgi third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-572cf2642d third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-f37895e500 third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-233241ccc7 third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-e1aedf3746 third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-651ba4626f third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-f5d072060b third party advisory
- bodhi.fedoraproject.org · FEDORA-2026-1885157e34 third party advisory
- ubuntu.com · USN-8101-1 third party advisory
- lists.suse.com · 024705.html third party advisory
- lists.suse.com · 024799.html third party advisory
- lists.suse.com · 024797.html third party advisory
- lists.suse.com · 024794.html third party advisory
- lists.suse.com · 024795.html third party advisory
- lists.suse.com · 024796.html third party advisory
- lists.suse.com · 024827.html third party advisory
- lists.suse.com · 024823.html third party advisory
- lists.suse.com · 024935.html third party advisory
- lists.suse.com · 024962.html third party advisory
- lists.opensuse.org · AJCRVCOHIXBPOWIY6K5PTFIISIXFBIOK third party advisory
- lists.suse.com · 025100.html third party advisory
- access.redhat.com · RHSA-2026:6619 third party advisory
- access.redhat.com · RHSA-2026:6729 third party advisory
- access.redhat.com · RHSA-2026:6730 third party advisory
- access.redhat.com · RHSA-2026:6502 third party advisory
- access.redhat.com · RHSA-2026:6540 third party advisory
- access.redhat.com · RHSA-2026:6620 third party advisory
- access.redhat.com · RHSA-2026:6539 third party advisory
- access.redhat.com · RHSA-2026:6617 third party advisory
- access.redhat.com · RHSA-2026:6731 third party advisory
- access.redhat.com · RHSA-2026:6736 third party advisory
- access.redhat.com · RHSA-2026:6915 third party advisory
- linux.oracle.com · ELSA-2026-6915.html third party advisory
- errata.build.resf.org · RLSA-2026:6915 third party advisory
- access.redhat.com · RHSA-2026:7711 third party advisory
- linux.oracle.com · ELSA-2026-7711.html third party advisory
- access.redhat.com · RHSA-2026:8259 third party advisory
- errata.build.resf.org · RLSA-2026:7711 third party advisory
- linux.oracle.com · ELSA-2026-8259.html third party advisory
- access.redhat.com · RHSA-2026:7239 third party advisory
- access.redhat.com · RHSA-2026:7243 third party advisory
- errata.build.resf.org · RLSA-2026:8259 third party advisory
- access.redhat.com · RHSA-2026:8423 third party advisory
- access.redhat.com · RHSA-2026:9832 third party advisory
- access.redhat.com · RHSA-2026:10065 third party advisory
- linux.oracle.com · ELSA-2026-11389.html third party advisory
- linux.oracle.com · ELSA-2026-11510.html third party advisory
- linux.oracle.com · ELSA-2026-11509.html third party advisory
- access.redhat.com · RHSA-2026:11768 third party advisory
- access.redhat.com · RHSA-2026:10097 third party advisory
- access.redhat.com · RHSA-2026:12274 third party advisory
- access.redhat.com · RHSA-2026:14773 third party advisory
- access.redhat.com · RHSA-2026:15087 third party advisory
- linux.oracle.com · ELSA-2026-6617.html third party advisory
- access.redhat.com · RHSA-2026:17596 third party advisory
- linux.oracle.com · ELSA-2026-22730.html third party advisory
- access.redhat.com · RHSA-2026:25096 third party advisory
- dell.com · dsa-2026-386-security-update-f third party advisory
- access.redhat.com · RHSA-2026:66348 third party advisory
- access.redhat.com · RHSA-2026:66336 third party advisory
- linux.oracle.com · ELSA-2026-66366-0.html third party advisory
- linux.oracle.com · ELSA-2026-66348-0.html third party advisory
- linux.oracle.com · ELSA-2026-66336-0.html third party advisory
- errata.build.resf.org · RLSA-2026:66348 third party advisory
- access.redhat.com · RHSA-2026:66366 third party advisory