Back to Security Advisories
High 2026-07-31

Vim Security Update — AlmaLinux 9 (ALSA-2026:47982)

AlmaLinux 9

Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455) * vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456) * vim: V…

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

* vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455)
* vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456)
* vim: V…

Type:
security

Severity:
important

Release date:
2026-07-31

Description:
Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

* vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455)
* vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456)
* vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693)
* vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion (CVE-2026-59856)
* vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 vim-X11-8.2.2637-26.el9_8.13.aarch64.rpm 024112d88f82bb62b0b2ce3dc64555dd19e4c68cd19ae557ffaeba3f737da14a
aarch64 vim-common-8.2.2637-26.el9_8.13.aarch64.rpm 52ebcf4480845be59d41c3b8d23d156fd432681f490d6c27adc8e78a4dce6d63
aarch64 vim-minimal-8.2.2637-26.el9_8.13.aarch64.rpm 6574d1040686f3aa7caed487293dcfed3fbfd80cc61bf7c29be011088b83b6e5
aarch64 vim-enhanced-8.2.2637-26.el9_8.13.aarch64.rpm c08444bee54e30fbbdd766d103976114fc17f5140e63a8b8eff1dc0b1fb51699
noarch vim-filesystem-8.2.2637-26.el9_8.13.noarch.rpm 1dce4bf19fab1f7744521428e9e7318704d0264b3f6f15609608cbc8630aff78
ppc64le vim-common-8.2.2637-26.el9_8.13.ppc64le.rpm 4907aeb9bd5ac28347cebc914373eaa9ec14a0e8a3e0adf94531a4a37670f237
ppc64le vim-enhanced-8.2.2637-26.el9_8.13.ppc64le.rpm 604fa0d945b842b623df60ac841b0c07951daaa4f9d7bde131ff205f50c28e52
ppc64le vim-minimal-8.2.2637-26.el9_8.13.ppc64le.rpm 6c970a621ca5afea37c854bce6e127c73f85904d1a95872e132bf0bb98da6950
ppc64le vim-X11-8.2.2637-26.el9_8.13.ppc64le.rpm 9c7364a30fcf89c46e4d6e8662339ad1053126a91ce9b378dd0661cd23919bcb
s390x vim-enhanced-8.2.2637-26.el9_8.13.s390x.rpm 4960e3869c2f2cea000178ae4e00f1316c66bd563d41eb7a816180926bcd1245
s390x vim-minimal-8.2.2637-26.el9_8.13.s390x.rpm 4bb5afb1d12444ba42f872f4edc68de107c2a0068ed964a91ce07580d036262f
s390x vim-common-8.2.2637-26.el9_8.13.s390x.rpm 4e6b843c6e24601821ba741abe58200566754d04fc06e27f34fa608e4cccd64e
s390x vim-X11-8.2.2637-26.el9_8.13.s390x.rpm c8be4a68f0a4a5b893d1007a31eb9eaedc9c7389fafddca58d6e6473101c7c31
x86_64 vim-minimal-8.2.2637-26.el9_8.13.x86_64.rpm 18a72424b5b9cac5e27a824349c1d6dc5bc7f7967693fd02f08e6e85aa3aedf3
x86_64 vim-enhanced-8.2.2637-26.el9_8.13.x86_64.rpm 1c840fd4bd75bf7d2656779bdbbe6736bff6ab6179a7df9eef016dc862d20141
x86_64 vim-X11-8.2.2637-26.el9_8.13.x86_64.rpm 2ddf650f86b0ae9f8b232c38c46d9690e8372387b3123880203b6efa76fa44c6
x86_64 vim-common-8.2.2637-26.el9_8.13.x86_64.rpm 3cd2655703e97072207e28c7a15aac407bc529f800458a49ca8652bbddbb857a

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

How to Apply the Fix

Update the affected packages on your server to the patched release, then restart the relevant services.

sudo dnf update
More Information

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System