Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34982

Опубликовано: 06 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.2

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The complete, guitabtooltip and printheader options are missing the P_MLE flag, allowing a modeline to be executed. Additionally, the mapset() function lacks a check_secure() call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

РелизСтатусПримечание
devel

not-affected

2:9.1.2141-1ubuntu4
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

released

2:8.1.2269-1ubuntu5.32+esm3
esm-infra/xenial

not-affected

code not present
jammy

released

2:8.2.3995-1ubuntu2.27
noble

released

2:9.1.0016-1ubuntu7.11
questing

released

2:9.1.0967-1ubuntu6.2
upstream

not-affected

9.2.0276

Показывать по

EPSS

Процентиль: 37%
0.0047
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
4 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

CVSS3: 8.2
nvd
4 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

CVSS3: 8.2
msrc
4 месяца назад

Vim modeline bypass via various options affects Vim < 9.2.0276

CVSS3: 8.2
debian
4 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

rocky
2 месяца назад

Important: vim security update

EPSS

Процентиль: 37%
0.0047
Низкий

8.2 High

CVSS3