vim-8.2.2637-26.el9_8.10.ML.1

エラータID: AXSA:2026-1480:21

Release date: 
Friday, August 7, 2026 - 15:15
Subject: 
vim-8.2.2637-26.el9_8.10.ML.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

* vim: command injection when decompressing .tgz archives (CVE-2026-46483)
* vim: Vim: Arbitrary Code Execution via crafted directory names (CVE-2026-47162)
* vim: Vim: Arbitrary code execution via Python omni-completion (CVE-2026-52858)
* vim: Vim: Arbitrary code execution via crafted step-definition patterns (CVE-2026-47167)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-46483
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(tartail) without the {special} flag, allowing a crafted archive filename to trigger Vim cmdline-special expansion and execute shell commands in the user's context. This vulnerability is fixed in 9.2.0479.
CVE-2026-47162
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~/.vim/.netrwhist. A directory name derived from the filesystem is interpolated into a single-quoted Vimscript string literal without escaping embedded single quotes, allowing a crafted directory name to break out of the string context and execute arbitrary Vimscript, including shell commands via system() and :!, the next time the history file is sourced. This issue has been patched in version 9.2.0495.
CVE-2026-47167
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under the repository's features/*/ or stories/*/ directories are embedded into a Ruby Kernel.eval argument without sufficient escaping, allowing a crafted pattern in an attacker-controlled repository to execute arbitrary Ruby (and through it arbitrary shell commands) when the user invokes a step-jump mapping ([d, ]d). This issue has been patched in version 9.2.0496.
CVE-2026-52858
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and from statements found in the current buffer through Python's import machinery. Because the buffer's working directory is on sys.path, opening a hostile .py file with a sibling Python package and invoking omni-completion runs that package's top-level code as the editing user. This issue has been patched in version 9.2.0561.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. vim-8.2.2637-26.el9_8.10.ML.1.src.rpm
    MD5: 05b0020b27824ab857017907ea29730e
    SHA-256: 908711f5d02a53d1f3d1c8bbdab03053e7bc3a9bd9a6806ea13048a46b6314d5
    Size: 12.25 MB

Asianux Server 9 for x86_64
  1. vim-common-8.2.2637-26.el9_8.10.ML.1.x86_64.rpm
    MD5: 8176057b9da3b5c835f78aa120d51e20
    SHA-256: 74bf94120f29f44ee0ab388b1c84ebfad57dca97aaacf33ab3299420bab90394
    Size: 6.97 MB
  2. vim-enhanced-8.2.2637-26.el9_8.10.ML.1.x86_64.rpm
    MD5: 0b5a313bdfd35fa03db460a730945691
    SHA-256: 1c960f8be99daa502eac7623ba2c24464477926d61b95613ed811880ae29dbb0
    Size: 1.75 MB
  3. vim-filesystem-8.2.2637-26.el9_8.10.ML.1.noarch.rpm
    MD5: f19e9449804ba8382adec08c1e49f8bc
    SHA-256: ef658f725531f0b85fe19b3eb44e62734a845cb4101498f2fe096fb3c0ff90e2
    Size: 11.48 kB
  4. vim-minimal-8.2.2637-26.el9_8.10.ML.1.x86_64.rpm
    MD5: 44a05ff88d7a130be6c544745628e487
    SHA-256: 8af7d559312e8d26b3ad3082f4ab9faae20af103aea8d7c91dbb0a6b592aa4bf
    Size: 672.71 kB
  5. vim-X11-8.2.2637-26.el9_8.10.ML.1.x86_64.rpm
    MD5: 6f81456e81dd85d63ddade5dc834b1ec
    SHA-256: 6fee9972f792c5e446294b23716cf4680acf0db8ea5db473255c5fe35f3a165b
    Size: 1.91 MB