- What: Security update for Vim editor
- Impact: Red Hat Enterprise Linux 10 systems
Red Hat Product Errata RHSA-2026:48650 - Security Advisory Issued: 2026-07-30 Updated: 2026-07-30 RHSA-2026:48650 - Security Advisory Overview Updated Packages Synopsis Important: vim security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for vim is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693) vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion (CVE-2026-59856) vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2492968 - CVE-2026-57455 vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() BZ - 2492972 - CVE-2026-57456 vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion BZ - 2492980 - CVE-2026-55693 vim: Vim: Out-of-bounds Write in Spell File Word Count BZ - 2498867 - CVE-2026-59856 vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion BZ - 2498868 - CVE-2026-59858 vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion CVEs CVE-2026-55693 CVE-2026-57455 CVE-2026-57456 CVE-2026-59856 CVE-2026-59858 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM vim-9.1.083-9.el10_2.12.src.rpm SHA-256: 500f3f1f75a5dd274525537d4f2b11ab13493f972e310d77f1ccc157c45d50de x86_64 vim-X11-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 56d4e43e2305c2f08e6705c83e94896d09f4c29a36cab1ae304d002ebf4cc4e0 vim-X11-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 46272bc42e3f80f4caaf708f6027f8e157be20526c4878a1ca12ff469b3d706a vim-X11-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 46272bc42e3f80f4caaf708f6027f8e157be20526c4878a1ca12ff469b3d706a vim-common-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: ba6f763567922e24b07c8d73a5bb489f3257ab371b5f0e977158b0525be30ef4 vim-data-9.1.083-9.el10_2.12.noarch.rpm SHA-256: 51411d5f6591332d88c24f37a7bad0bea2d44ef84a47a9bb5a3354a3bbfce10f vim-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 4df44719264ba5ea1f5fe4c88891ea1a4c3333a5ccac478f7d0b5078c373a9e4 vim-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 4df44719264ba5ea1f5fe4c88891ea1a4c3333a5ccac478f7d0b5078c373a9e4 vim-debugsource-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: cae94848b2e242d8ef1941991e08dbf0c1a7e2f791680be24428e3d929d79b26 vim-debugsource-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: cae94848b2e242d8ef1941991e08dbf0c1a7e2f791680be24428e3d929d79b26 vim-enhanced-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 0e734dab8e973183ba54017eaff71491411d50639145cf25b49c8d6e054ae092 vim-enhanced-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 05b01873c17ea872cd2e37c776952c24fbbebbd15e10063eb0ba89af5b1862a6 vim-enhanced-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 05b01873c17ea872cd2e37c776952c24fbbebbd15e10063eb0ba89af5b1862a6 vim-filesystem-9.1.083-9.el10_2.12.noarch.rpm SHA-256: cc77ce5d52ddcc1ba66aca79f4ba3548cf123379382c41d69fa1e679eb47d3c3 vim-minimal-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 45d0c9aa377e35799ba2a7260a72ee9fa89e1cd033c2b079cda070f1ae1dc093 vim-minimal-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: a14801a85b343be5fd16040d213c1a4b9f752256ebb9444b99ba039277b95d3c vim-minimal-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: a14801a85b343be5fd16040d213c1a4b9f752256ebb9444b99ba039277b95d3c xxd-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 021212b765a8297ecb9fc43d851ec3d19166a16aaa64e8ccdc401487833a63aa xxd-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: b0f98b40ad1ffba98249f8d88f787bd683b025ced47b4cd2ac3a403bc30cc820 xxd-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: b0f98b40ad1ffba98249f8d88f787bd683b025ced47b4cd2ac3a403bc30cc820 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM vim-9.1.083-9.el10_2.12.src.rpm SHA-256: 500f3f1f75a5dd274525537d4f2b11ab13493f972e310d77f1ccc157c45d50de x86_64 vim-X11-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 56d4e43e2305c2f08e6705c83e94896d09f4c29a36cab1ae304d002ebf4cc4e0 vim-X11-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 46272bc42e3f80f4caaf708f6027f8e157be20526c4878a1ca12ff469b3d706a vim-X11-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 46272bc42e3f80f4caaf708f6027f8e157be20526c4878a1ca12ff469b3d706a vim-common-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: ba6f763567922e24b07c8d73a5bb489f3257ab371b5f0e977158b0525be30ef4 vim-data-9.1.083-9.el10_2.12.noarch.rpm SHA-256: 51411d5f6591332d88c24f37a7bad0bea2d44ef84a47a9bb5a3354a3bbfce10f vim-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 4df44719264ba5ea1f5fe4c88891ea1a4c3333a5ccac478f7d0b5078c373a9e4 vim-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 4df44719264ba5ea1f5fe4c88891ea1a4c3333a5ccac478f7d0b5078c373a9e4 vim-debugsource-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: cae94848b2e242d8ef1941991e08dbf0c1a7e2f791680be24428e3d929d79b26 vim-debugsource-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: cae94848b2e242d8ef1941991e08dbf0c1a7e2f791680be24428e3d929d79b26 vim-enhanced-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 0e734dab8e973183ba54017eaff71491411d50639145cf25b49c8d6e054ae092 vim-enhanced-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 05b01873c17ea872cd2e37c776952c24fbbebbd15e10063eb0ba89af5b1862a6 vim-enhanced-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 05b01873c17ea872cd2e37c776952c24fbbebbd15e10063eb0ba89af5b1862a6 vim-filesystem-9.1.083-9.el10_2.12.noarch.rpm SHA-256: cc77ce5d52ddcc1ba66aca79f4ba3548cf123379382c41d69fa1e679eb47d3c3 vim-minimal-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 45d0c9aa377e35799ba2a7260a72ee9fa89e1cd033c2b079cda070f1ae1dc093 vim-minimal-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: a14801a85b343be5fd16040d213c1a4b9f752256ebb9444b99ba039277b95d3c vim-minimal-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: a14801a85b343be5fd16040d213c1a4b9f752256ebb9444b99ba039277b95d3c xxd-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: 021212b765a8297ecb9fc43d851ec3d19166a16aaa64e8ccdc401487833a63aa xxd-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: b0f98b40ad1ffba98249f8d88f787bd683b025ced47b4cd2ac3a403bc30cc820 xxd-debuginfo-9.1.083-9.el10_2.12.x86_64.rpm SHA-256: b0f98b40ad1ffba98249f8d88f787bd683b025ced47b4cd2ac3a403bc30cc820 Red Hat Enterprise Linux for IBM z Systems 10 SRPM vim-9.1.083-9.el10_2.12.src.rpm SHA-256: 500f3f1f75a5dd274525537d4f2b11ab13493f972e310d77f1ccc157c45d50de s390x vim-X11-9.1.083-9.el10_2.12.s390x.rpm SHA-256: f63f4b018acd459c8df2ddf5700c35441361a7c0a4e707279106ab5752b42562 vim-X11-debuginfo-9.1.083-9.el10_2.12.s390x.rpm SHA-256: 3d257e7459290479e8fd278a2eaf294f6e863b0e23d71b1855d70d3ffbd11eef vim-X11-debuginfo-9.1.083-9.el10_2.12.s390x.rpm SHA-256: 3d257e7459290479e8fd278a2eaf294f6e863b0e23d71b1855d70d3ffbd11eef vim-common-9.1.083-9.el10_2.12.s390x.rpm SHA-256: 9d6c6bdfd0dcaecc87c161eb38c53fede6ea3342c863769257e909d043b219fe vim-data-9.1.083-9.el10_2.12.noarch.rpm SHA-256: 51411d5f6591332d88c24f37a7bad0bea2d44ef84a47a9bb5a3354a3bbfce10f vim-debuginfo-9.1.083-9.el10_2.12.s390x.rpm SHA-256: 0d035dfc26519c92aa332515870bf51fe8dfb1b3dfd38c9ea401984469682588 vim-debuginfo-9.1.083-9.el10_2.12.s390x.rpm SHA-256: 0d035dfc26519c92aa332515870bf51fe8dfb1b3dfd38c9ea401984469682588 vim-debugsource-9.1.083-9.el10_2.12.s390x.rpm SHA-256: 2dbc3e3379c8bc98489002535f4ed72077d8a2335162846f122d471c2176e8cc vim-debugsource-9.1.083-9.el10_2.12.s390x.rpm SHA-256: 2dbc3e3379c8bc98489002535f4ed72077d8a2335162846f122d471c2176e8cc vim-enhanced-9.1.083-9.el10_2.12.s390x.rpm SHA-256: c9f8c78aba5fd2b3a580deb98efdcfaef9def5e6369987a27fe8366a1c37521c vim-enhanced-debuginfo-9.1.083-9.el10_2.12.s390x.rpm SHA-256: bb305a036679bed839220521a24ac7ad50f0f461fa5e6432cc33580830e1cdc0 vim-enhanced-debuginfo-9.1.083-9.el10_2.12.s390x.rpm SHA-256: bb305a036679