Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-51401

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

A flaw was found in Vim. A local attacker could exploit a vulnerability in the vms_fixfilename() function, allowing them to execute arbitrary code on the system. This could lead to a complete compromise of the affected system.

Отчет

Red Hat Enterprise Linux and Fedora build Vim against the POSIX/Linux platform layer (os_unix.c). The vulnerable function, vms_fixfilename(), is defined in os_vms.c, which provides OpenVMS-specific support and is never compiled into Red Hat's or Fedora's Vim packages. As a result, none of Red Hat's shipped Vim builds contain the affected code path.

Меры по смягчению последствий

No mitigation is required. Red Hat does not ship any product containing the vulnerable code path - the affected function is confined to Vim's OpenVMS platform support, which is not included in Red Hat Enterprise Linux or Fedora builds.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10vimNot affected
Red Hat Enterprise Linux 6vimNot affected
Red Hat Enterprise Linux 7vimNot affected
Red Hat Enterprise Linux 8vimNot affected
Red Hat Enterprise Linux 9vimNot affected
Red Hat Hardened ImagesvimNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-641
https://bugzilla.redhat.com/show_bug.cgi?id=2511255vim: Vim: Arbitrary code execution via vms_fixfilename() function

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
5 дней назад

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

CVSS3: 7.7
nvd
5 дней назад

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

CVSS3: 7.7
debian
5 дней назад

An issue in Vim Project v9.2.0389 and earlier allows a local attacker ...

CVSS3: 7.7
github
5 дней назад

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

EPSS

Процентиль: 4%
0.00139
Низкий

7.8 High

CVSS3