OESA-2026-3596

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3596
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3596.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3596
Upstream
Published
2026-09-05T15:03:00Z
Modified
2026-09-05T15:16:25.730983333Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
vim security update
Details

Vim is an advanced text editor that seeks to provide the power of the de-facto Unix editor 'Vi', with a more complete feature set. Vim is a highly configurable text editor built to enable efficient text editing. It is an improved version of the vi editor distributed with most UNIX systems.

Security Fix(es):

Vim is an open source, command line text editor. Prior to 9.2.0846, setsofo() in src/spellfile.c reuses slsalfirst[] without resetting values left by setsalfirst(), so a crafted spell file containing an SNSAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.(CVE-2026-73072)

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, allowing an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion with CTRL-X CTRL-O on a member access whose type is resolved from that tags file. This issue is fixed in version 9.2.0845.(CVE-2026-73073)

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.(CVE-2026-73076)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP4 / vim

Package

Name
vim
Purl
pkg:rpm/openEuler/vim&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0-59.oe2003sp4

Ecosystem specific

{
    "src": [
        "vim-9.0-59.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "vim-X11-9.0-59.oe2003sp4.x86_64.rpm",
        "vim-common-9.0-59.oe2003sp4.x86_64.rpm",
        "vim-debuginfo-9.0-59.oe2003sp4.x86_64.rpm",
        "vim-debugsource-9.0-59.oe2003sp4.x86_64.rpm",
        "vim-enhanced-9.0-59.oe2003sp4.x86_64.rpm",
        "vim-minimal-9.0-59.oe2003sp4.x86_64.rpm"
    ],
    "aarch64": [
        "vim-X11-9.0-59.oe2003sp4.aarch64.rpm",
        "vim-common-9.0-59.oe2003sp4.aarch64.rpm",
        "vim-debuginfo-9.0-59.oe2003sp4.aarch64.rpm",
        "vim-debugsource-9.0-59.oe2003sp4.aarch64.rpm",
        "vim-enhanced-9.0-59.oe2003sp4.aarch64.rpm",
        "vim-minimal-9.0-59.oe2003sp4.aarch64.rpm"
    ],
    "noarch": [
        "vim-filesystem-9.0-59.oe2003sp4.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3596.json"