Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20540-1

Опубликовано: 15 апр. 2026
Источник: suse-cvrf

Описание

Security update for vim

This update for vim fixes the following issues:

  • CVE-2026-33412: command injection via newline in glob() (bsc#1259985).
  • CVE-2026-34714: crafted file can allow code execution (bsc#1261191).
  • CVE-2026-34982: Vim modeline bypass via various options (bsc#1261271).

Список пакетов

openSUSE Leap 16.0
gvim-9.2.0280-160000.1.1
vim-9.2.0280-160000.1.1
vim-data-9.2.0280-160000.1.1
vim-data-common-9.2.0280-160000.1.1
vim-small-9.2.0280-160000.1.1
xxd-9.2.0280-160000.1.1

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.


Затронутые продукты
openSUSE Leap 16.0:gvim-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-data-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-data-common-9.2.0280-160000.1.1

Ссылки

Описание

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.


Затронутые продукты
openSUSE Leap 16.0:gvim-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-data-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-data-common-9.2.0280-160000.1.1

Ссылки

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.


Затронутые продукты
openSUSE Leap 16.0:gvim-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-data-9.2.0280-160000.1.1
openSUSE Leap 16.0:vim-data-common-9.2.0280-160000.1.1

Ссылки