Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1347-1

Опубликовано: 15 апр. 2026
Источник: suse-cvrf

Описание

Security update for vim

This update for vim fixes the following issues:

Update to version 9.2.0280.

  • CVE-2026-34982: missing input validation allows for a modeline sandbox bypass and can lead to arbitrary OS command execution (bsc#1261271).
  • CVE-2026-34714: missing checks allow for a tabpanel modeline escape and can lead to arbitrary OS command execution (bsc#1261191).
  • CVE-2026-33412: improper escaping of newline characters allows for command injection in glob and can lead to arbitrary code execution (bsc#1259985).

Список пакетов

Image SLES12-SP5-Azure-BYOS
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-BYOS
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-SAP-BYOS
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-SAP-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-Standard-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-EC2-BYOS
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-EC2-ECS-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-EC2-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-EC2-SAP-BYOS
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-EC2-SAP-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-GCE-BYOS
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-GCE-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-GCE-SAP-BYOS
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-GCE-SAP-On-Demand
vim-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
SUSE Linux Enterprise Server 12 SP5-LTSS
gvim-9.2.0280-17.62.1
vim-9.2.0280-17.62.1
vim-data-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
gvim-9.2.0280-17.62.1
vim-9.2.0280-17.62.1
vim-data-9.2.0280-17.62.1
vim-data-common-9.2.0280-17.62.1

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:vim-9.2.0280-17.62.1
Image SLES12-SP5-Azure-BYOS:vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-BYOS:vim-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-BYOS:vim-data-common-9.2.0280-17.62.1

Ссылки

Описание

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:vim-9.2.0280-17.62.1
Image SLES12-SP5-Azure-BYOS:vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-BYOS:vim-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-BYOS:vim-data-common-9.2.0280-17.62.1

Ссылки

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.


Затронутые продукты
Image SLES12-SP5-Azure-BYOS:vim-9.2.0280-17.62.1
Image SLES12-SP5-Azure-BYOS:vim-data-common-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-BYOS:vim-9.2.0280-17.62.1
Image SLES12-SP5-Azure-HPC-BYOS:vim-data-common-9.2.0280-17.62.1

Ссылки