Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34982

Опубликовано: 06 апр. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the P_MLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a check_secure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

A flaw was found in Vim. A modeline is used to set specific editor options directly from a text file. However, the complete, guitabtooltip, printheader options and the mapset function lack proper security checks, allowing an attacker to bypass restrictions and cause arbitrary OS command execution.

Отчет

To exploit this vulnerability, an attacker needs to convince a user to open a specially crafted file. The arbitrary OS command execution is restricted to the privileges of the user running Vim, limiting the potential of a full system compromise.

Меры по смягчению последствий

To mitigate this issue, disable the modeline support by adding the following command to the Vim configuration file:

set nomodeline

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6vimAffected
Red Hat Enterprise Linux 7vimAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10vimFixedRHSA-2026:1138928.04.2026
Red Hat Enterprise Linux 10vimFixedRHSA-2026:1907319.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportvimFixedRHSA-2026:3090029.06.2026
Red Hat Enterprise Linux 8vimFixedRHSA-2026:1150929.04.2026
Red Hat Enterprise Linux 8vimFixedRHSA-2026:1150929.04.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportvimFixedRHSA-2026:3345330.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnvimFixedRHSA-2026:3345330.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2455400vim: arbitrary command execution via modeline sandbox bypass

EPSS

Процентиль: 38%
0.0047
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
4 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

CVSS3: 8.2
nvd
4 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

CVSS3: 8.2
msrc
4 месяца назад

Vim modeline bypass via various options affects Vim < 9.2.0276

CVSS3: 8.2
debian
4 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

rocky
2 месяца назад

Important: vim security update

EPSS

Процентиль: 38%
0.0047
Низкий

8.2 High

CVSS3