[ALSA-2026:7711] Important: vim security update
Type:
security
Severity:
important
Release date:
2026-04-14
Description:
Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417) * vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421) * vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch vim-filesystem-9.1.083-6.el10_1.3.noarch.rpm 22509b33747db53b66178eda558bc87b2ce9adb046b4cfa0848eb38bc552c79c
noarch vim-data-9.1.083-6.el10_1.3.noarch.rpm c6b1deaee2ad61a57b36d079ad281c08fbf8d27a6147d7e78db9efa5915caaef
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.