Описание
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the P_MLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a check_secure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
A flaw was found in Vim. A modeline is used to set specific editor options directly from a text file. However, the complete, guitabtooltip, printheader options and the mapset function lack proper security checks, allowing an attacker to bypass restrictions and cause arbitrary OS command execution.
Отчет
To exploit this vulnerability, an attacker needs to convince a user to open a specially crafted file. The arbitrary OS command execution is restricted to the privileges of the user running Vim, limiting the potential of a full system compromise.
Меры по смягчению последствий
To mitigate this issue, disable the modeline support by adding the following command to the Vim configuration file:
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | vim | Affected | ||
| Red Hat Enterprise Linux 7 | vim | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Affected | ||
| Red Hat Enterprise Linux 10 | vim | Fixed | RHSA-2026:11389 | 28.04.2026 |
| Red Hat Enterprise Linux 10 | vim | Fixed | RHSA-2026:19073 | 19.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | vim | Fixed | RHSA-2026:30900 | 29.06.2026 |
| Red Hat Enterprise Linux 8 | vim | Fixed | RHSA-2026:11509 | 29.04.2026 |
| Red Hat Enterprise Linux 8 | vim | Fixed | RHSA-2026:11509 | 29.04.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | vim | Fixed | RHSA-2026:33453 | 30.06.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | vim | Fixed | RHSA-2026:33453 | 30.06.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
Vim modeline bypass via various options affects Vim < 9.2.0276
Vim is an open source, command line text editor. Prior to version 9.2. ...
EPSS
8.2 High
CVSS3