Red Hat Product Errata RHSA-2026:30900 - Security Advisory Issued: 2026-06-29 Updated: 2026-06-29 RHSA-2026:30900 - Security Advisory Overview Updated Packages Synopsis Important: vim security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for vim is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) vim: command injection when decompressing .tgz archives (CVE-2026-46483) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2455400 - CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass BZ - 2455542 - CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass BZ - 2461614 - CVE-2026-41411 vim: Vim: Command injection allows arbitrary code execution via malicious tag files BZ - 2477915 - CVE-2026-46483 vim: command injection when decompressing .tgz archives CVEs CVE-2026-34982 CVE-2026-35177 CVE-2026-41411 CVE-2026-46483 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM vim-9.1.083-5.el10_0.3.src.rpm SHA-256: 54efa0a004594d044c850da2648854173b6ef743f70d39112698d6375cb8a6ad x86_64 vim-X11-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: 4af7262b8297386cd1eb1e8cd5075962e2b388c94cfa2c47739b437952c6c20e vim-X11-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: 925390014fa745bd66408442555f797724ca57046758f0e7c0185038762f4134 vim-X11-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: 925390014fa745bd66408442555f797724ca57046758f0e7c0185038762f4134 vim-common-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: 711e5a5ce2622d1c032f40961eec5817e5a9072d66a58c627c13ce234f758db0 vim-data-9.1.083-5.el10_0.3.noarch.rpm SHA-256: b09237d71a768c780083991ff2f6e6b4932a9d0a14ed937df9e6ea26bb917a33 vim-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: a66db5b2d63c9e27cc47f72613c1466d028c9bad57f53967011f8232c7b40334 vim-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: a66db5b2d63c9e27cc47f72613c1466d028c9bad57f53967011f8232c7b40334 vim-debugsource-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: c830563ad7f34f5ac4cff73e13f337243ef1416c7dd4357ee75890f0b5a838ee vim-debugsource-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: c830563ad7f34f5ac4cff73e13f337243ef1416c7dd4357ee75890f0b5a838ee vim-enhanced-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: 02755bb57fb07526441d8fc079376d68abb41ca32717f6b7309cea6e0117770e vim-enhanced-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: e18f7a9402d1f4bcf21d262f91ba7a96c95e949a5fd0311028384378a39c1c03 vim-enhanced-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: e18f7a9402d1f4bcf21d262f91ba7a96c95e949a5fd0311028384378a39c1c03 vim-filesystem-9.1.083-5.el10_0.3.noarch.rpm SHA-256: 22d477db5c9bbeed01fba6dcdf14138d69042f5ad4a6bf0146da2eb2bd62066d vim-minimal-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: 2e731d9497d5255a78b00e381ba264082ef2137e36bd5a5f568c4b39a335898f vim-minimal-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: dd591eeba5992ef24fda92fb8cec87161d550b586d2e2da1549d3add583775c8 vim-minimal-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: dd591eeba5992ef24fda92fb8cec87161d550b586d2e2da1549d3add583775c8 xxd-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: 7114491581e81fbf3dcba49ce19c1ce74b9f85541d54c9316101167327beaa45 xxd-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: c95a216e77316f1ed753bb45ed186b5eb17ce7eb1e6a8db5e6a7b61dc8e4b400 xxd-debuginfo-9.1.083-5.el10_0.3.x86_64.rpm SHA-256: c95a216e77316f1ed753bb45ed186b5eb17ce7eb1e6a8db5e6a7b61dc8e4b400 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM vim-9.1.083-5.el10_0.3.src.rpm SHA-256: 54efa0a004594d044c850da2648854173b6ef743f70d39112698d6375cb8a6ad s390x vim-X11-9.1.083-5.el10_0.3.s390x.rpm SHA-256: ec5ad27528e4c2f5d1038d2ba9a17fb3542c523b0f42aa563261973041c55fe0 vim-X11-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 86cbc607c09b2e8b434ae21a2bce5e86b74bbafaf632932b2f840d6c9882c9cd vim-X11-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 86cbc607c09b2e8b434ae21a2bce5e86b74bbafaf632932b2f840d6c9882c9cd vim-common-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 25535c449f353dee4e6c078e1d80b80bd5505acb7e9ac235bc8eba846f4d230b vim-data-9.1.083-5.el10_0.3.noarch.rpm SHA-256: b09237d71a768c780083991ff2f6e6b4932a9d0a14ed937df9e6ea26bb917a33 vim-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 3715e1541d56e27d1dc87c2bc63645422585f9adabbb5bd7bd5f9bae6ff8ad57 vim-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 3715e1541d56e27d1dc87c2bc63645422585f9adabbb5bd7bd5f9bae6ff8ad57 vim-debugsource-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 9e0f18c5856238bcab2590d75d9f5d3fad1d333f71ee89f590e1a3007ad48b22 vim-debugsource-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 9e0f18c5856238bcab2590d75d9f5d3fad1d333f71ee89f590e1a3007ad48b22 vim-enhanced-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 9d061e4ccd89aaba8fe77481579cf713576780f0a2c871c03bdd226616276224 vim-enhanced-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: cdcf9fd1788c021063db504f85f69bf8a7c0521f88c2b77ce8bfa573db59bd26 vim-enhanced-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: cdcf9fd1788c021063db504f85f69bf8a7c0521f88c2b77ce8bfa573db59bd26 vim-filesystem-9.1.083-5.el10_0.3.noarch.rpm SHA-256: 22d477db5c9bbeed01fba6dcdf14138d69042f5ad4a6bf0146da2eb2bd62066d vim-minimal-9.1.083-5.el10_0.3.s390x.rpm SHA-256: ea7f261902480506a007bc5394cb5f947e7537cd37e30fe0550f1e535bba3140 vim-minimal-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: e8dfc3c617d3ce983bf0d0894cb4907dd15eb13c6173f0c4db6bdf804bb85023 vim-minimal-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: e8dfc3c617d3ce983bf0d0894cb4907dd15eb13c6173f0c4db6bdf804bb85023 xxd-9.1.083-5.el10_0.3.s390x.rpm SHA-256: b433dc008b26660649e15857501f045247f56fec6a79d9bcdb89f4724dc7df93 xxd-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 0a6a6ae2cbfc018b746df11f8335f83369f2f7d5fda3d21cdb854d3d6edfeb21 xxd-debuginfo-9.1.083-5.el10_0.3.s390x.rpm SHA-256: 0a6a6ae2cbfc018b746df11f8335f83369f2f7d5fda3d21cdb854d3d6edfeb21 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM vim-9.1.083-5.el10_0.3.src.rpm SHA-256: 54efa0a004594d044c850da2648854173b6ef743f70d39112698d6375cb8a6ad ppc64le vim-X11-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 86351d0682e95efca34e239708c2e373b1c1b7eb47df7f4d6a9129052c912612 vim-X11-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 114582c6b0650c149c5aafad67dce0631c8c38a08a87e933f616c5832395a07a vim-X11-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 114582c6b0650c149c5aafad67dce0631c8c38a08a87e933f616c5832395a07a vim-common-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: cd6126dc45b6124d99837aac4c37b12704d50a47cd3f84f20b1e461d5b8709fd vim-data-9.1.083-5.el10_0.3.noarch.rpm SHA-256: b09237d71a768c780083991ff2f6e6b4932a9d0a14ed937df9e6ea26bb917a33 vim-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: de9dc8cfe36854faf3388981948de859fc93090d4540b7f0099f7cd75220412d vim-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: de9dc8cfe36854faf3388981948de859fc93090d4540b7f0099f7cd75220412d vim-debugsource-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 9d9f30922f70f905c9995122fd53308fdfc00545e921fac713028290bf765c5a vim-debugsource-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 9d9f30922f70f905c9995122fd53308fdfc00545e921fac713028290bf765c5a vim-enhanced-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 7d305cf133b01cfd39ad2b45bf759692a722cc69601a8e0dbf16b7d9716ae453 vim-enhanced-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 1d68157aac698dfda2e9fcd66f7fbb0c281dfadcb417f006b7b7557b297a7edb vim-enhanced-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 1d68157aac698dfda2e9fcd66f7fbb0c281dfadcb417f006b7b7557b297a7edb vim-filesystem-9.1.083-5.el10_0.3.noarch.rpm SHA-256: 22d477db5c9bbeed01fba6dcdf14138d69042f5ad4a6bf0146da2eb2bd62066d vim-minimal-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: ecff4b10b830a08b5413401a00adcb86573400a2f7f51e05f1536b6566e4fce9 vim-minimal-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: c288bf2db4c3abc341f5b2ea7af7a9458409048625758d4c411e93162a4cb2ce vim-minimal-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: c288bf2db4c3abc341f5b2ea7af7a9458409048625758d4c411e93162a4cb2ce xxd-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 7d9384c2eb616c77d6f8fbee440e070c27bc96ebe393b62d97d3a9dae802de36 xxd-debuginfo-9.1.083-5.el10_0.3.ppc64le.rpm SHA-256: 27a85
This Red Hat security advisory addresses four vulnerabilities in Vim, including a high-severity sandbox bypass allowing arbitrary command execution via modeline (CVE-2026-34982, CVSS 8.2) and three medium-severity flaws involving command injection and arbitrary file overwrite via malicious archives and tag files. The affected versions are Vim prior to 9.2.0276, 9.2.0280, and 9.2.0357, depending on the specific CVE. The fix requires applying the provided Red Hat package update for RHEL 10.0 EUS.