- What: A security update for vim addresses a vulnerability that allows arbitrary command execution via modeline sandbox bypass
- Impact: Affected systems include Red Hat Enterprise Linux 8.4 and related versions
Red Hat Product Errata RHSA-2026:33453 - Security Advisory Issued: 2026-06-30 Updated: 2026-06-30 RHSA-2026:33453 - Security Advisory Overview Updated Packages Synopsis Important: vim security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for vim is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982) vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass (CVE-2026-35177) vim: Vim: Command injection allows arbitrary code execution via malicious tag files (CVE-2026-41411) vim: command injection when decompressing .tgz archives (CVE-2026-46483) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2455400 - CVE-2026-34982 vim: arbitrary command execution via modeline sandbox bypass BZ - 2455542 - CVE-2026-35177 vim: zip.vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass BZ - 2461614 - CVE-2026-41411 vim: Vim: Command injection allows arbitrary code execution via malicious tag files BZ - 2477915 - CVE-2026-46483 vim: command injection when decompressing .tgz archives CVEs CVE-2026-34982 CVE-2026-35177 CVE-2026-41411 CVE-2026-46483 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM vim-8.0.1763-15.el8_4.2.src.rpm SHA-256: 6881436f13d6c9a463e8117d29e8bcc7d79a427d9b2ed0ebce5c5b93b7cdb115 x86_64 vim-X11-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 67816dcc2e1047b890c825c565df4a4b0f8ff31e8f8effc468612b2529b4ae00 vim-X11-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: a42489c4f2f1789bab5a1ef4671ed2f3192adeb4ecc75509d33f6c036294f96e vim-X11-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: a42489c4f2f1789bab5a1ef4671ed2f3192adeb4ecc75509d33f6c036294f96e vim-common-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 4c47b53fd31092c64ff2a65cdb6410fb1d7f7ad263b136651f931d421f3d48d4 vim-common-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 68bcbf2dae49189ef0efc7721814055fc1c3ba6a73d4b5e831d7b0d7c02f9c3c vim-common-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 68bcbf2dae49189ef0efc7721814055fc1c3ba6a73d4b5e831d7b0d7c02f9c3c vim-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 0b8c27c63281486d8c4be05166728be9c7469bf70f3115da4b71e11cdbd3deb5 vim-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 0b8c27c63281486d8c4be05166728be9c7469bf70f3115da4b71e11cdbd3deb5 vim-debugsource-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: fb81c552f602a5ca232732f2a008dcd556e9d5b77be1190ddefbf77a25f2542c vim-debugsource-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: fb81c552f602a5ca232732f2a008dcd556e9d5b77be1190ddefbf77a25f2542c vim-enhanced-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: c7f5cd1a6424f49db2ea4c06b8649a6f7869270015f2778858e8675c44f3bc46 vim-enhanced-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 78015e1be6578c0761e0fda9c2630952dd301788bc20c49b50ce7b5c043ff9a5 vim-enhanced-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 78015e1be6578c0761e0fda9c2630952dd301788bc20c49b50ce7b5c043ff9a5 vim-filesystem-8.0.1763-15.el8_4.2.noarch.rpm SHA-256: 68cab8ec12a434713d933736ce08daa88a39e6c50f281676a6246745ac7733f3 vim-minimal-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: aea033bf6ca8038610382e3ffd0489c4d4b5e21f022496ab6a58876038e0690e vim-minimal-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 9710f88a66d310bb2578b64159b97c3a09b440e4b2d6742a0e46e9f3b802b497 vim-minimal-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 9710f88a66d310bb2578b64159b97c3a09b440e4b2d6742a0e46e9f3b802b497 Red Hat Enterprise Linux Server - AUS 8.4 SRPM vim-8.0.1763-15.el8_4.2.src.rpm SHA-256: 6881436f13d6c9a463e8117d29e8bcc7d79a427d9b2ed0ebce5c5b93b7cdb115 x86_64 vim-X11-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 67816dcc2e1047b890c825c565df4a4b0f8ff31e8f8effc468612b2529b4ae00 vim-X11-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: a42489c4f2f1789bab5a1ef4671ed2f3192adeb4ecc75509d33f6c036294f96e vim-X11-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: a42489c4f2f1789bab5a1ef4671ed2f3192adeb4ecc75509d33f6c036294f96e vim-common-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 4c47b53fd31092c64ff2a65cdb6410fb1d7f7ad263b136651f931d421f3d48d4 vim-common-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 68bcbf2dae49189ef0efc7721814055fc1c3ba6a73d4b5e831d7b0d7c02f9c3c vim-common-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 68bcbf2dae49189ef0efc7721814055fc1c3ba6a73d4b5e831d7b0d7c02f9c3c vim-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 0b8c27c63281486d8c4be05166728be9c7469bf70f3115da4b71e11cdbd3deb5 vim-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 0b8c27c63281486d8c4be05166728be9c7469bf70f3115da4b71e11cdbd3deb5 vim-debugsource-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: fb81c552f602a5ca232732f2a008dcd556e9d5b77be1190ddefbf77a25f2542c vim-debugsource-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: fb81c552f602a5ca232732f2a008dcd556e9d5b77be1190ddefbf77a25f2542c vim-enhanced-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: c7f5cd1a6424f49db2ea4c06b8649a6f7869270015f2778858e8675c44f3bc46 vim-enhanced-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 78015e1be6578c0761e0fda9c2630952dd301788bc20c49b50ce7b5c043ff9a5 vim-enhanced-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 78015e1be6578c0761e0fda9c2630952dd301788bc20c49b50ce7b5c043ff9a5 vim-filesystem-8.0.1763-15.el8_4.2.noarch.rpm SHA-256: 68cab8ec12a434713d933736ce08daa88a39e6c50f281676a6246745ac7733f3 vim-minimal-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: aea033bf6ca8038610382e3ffd0489c4d4b5e21f022496ab6a58876038e0690e vim-minimal-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 9710f88a66d310bb2578b64159b97c3a09b440e4b2d6742a0e46e9f3b802b497 vim-minimal-debuginfo-8.0.1763-15.el8_4.2.x86_64.rpm SHA-256: 9710f88a66d310bb2578b64159b97c3a09b440e4b2d6742a0e46e9f3b802b497 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .