Vim bug can crash services
vim has a CERT-Bund advisory for CVE-2026-59857 in versions before 9.2.0725. An attacker can exploit a vulnerability in vim to carry out a denial of service attack.
- Severity
- Not scoredNo CVSS score recorded
- Fix
- Fixed in 9.2.0725Fix recorded yesterday
- Affected versions
- before 9.2.0725
- Affects
- vim+4 more
- Exploited
- Not confirmedNo confirmation recorded
How it works
An attacker can exploit a vulnerability in vim to carry out a denial of service attack.
What to do
Check your vim version. If it is before 9.2.0725, this advisory applies.
Update vim to 9.2.0725 or newer.
Technical details
Affected software: vim, Linux, Sonstiges, UNIX, Windows
An attacker can exploit a vulnerability in vim to carry out a denial of service attack. The advisory tracks CVE-2026-59857. In CERT-Bund's CSAF data, affected versions are before 9.2.0725, and the fixed version is 9.2.0725. Affected operating systems listed by CERT-Bund: Linux, Sonstiges, UNIX, Windows.
References
- wid.cert-bund.de · wid-sec-w-2026-2059.json technical description
- github.com · GHSA-m3hf-xcm3-xhm2 vendor advisory
- ubuntu.com · USN-8541-1 third party advisory
- lists.opensuse.org · KITIEWVI4YZXCCOUXKMIC7PBIBXINV2F third party advisory
- lists.suse.com · 027765.html third party advisory
- lists.suse.com · 027752.html third party advisory
- lists.suse.com · 027861.html third party advisory
- lists.suse.com · 027846.html third party advisory
- lists.suse.com · 027838.html third party advisory
- lists.suse.com · 027830.html third party advisory
- lists.suse.com · 027921.html third party advisory
- lists.suse.com · 027931.html third party advisory
- lists.suse.com · 027926.html third party advisory
- lists.suse.com · 028106.html third party advisory
- alas.aws.amazon.com · ALAS2-2026-3883.html third party advisory
- dell.com · dsa-2026-386-security-update-f third party advisory
- access.redhat.com · RHSA-2026:66336 third party advisory
- access.redhat.com · RHSA-2026:66348 third party advisory
- linux.oracle.com · ELSA-2026-66348-0.html third party advisory
- errata.build.resf.org · RLSA-2026:66348 third party advisory
- linux.oracle.com · ELSA-2026-66336-0.html third party advisory
- access.redhat.com · RHSA-2026:66366 third party advisory
- linux.oracle.com · ELSA-2026-66366-0.html third party advisory