Vim Security Update — AlmaLinux 9 (ALSA-2026:47982)
This is a security release for AlmaLinux 9. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Команды исправления
EL8+ (AlmaLinux/CloudLinux/Rocky)
sudo dnf update
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a change in AlmaLinux 9 software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Vim (Vi IMproved) is an updated and improved version of the vi editor.
Security Fix(es):
* vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455)
* vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456)
* vim: V…
Type:
security
Severity:
important
Release date:
2026-07-31
Description:
Vim (Vi IMproved) is an updated and improved version of the vi editor.
Security Fix(es):
* vim: Vim: Denial of Service via stack out-of-bounds write in spell_soundfold_sofo() (CVE-2026-57455)
* vim: Vim: Arbitrary code execution via malicious docstrings in Python omni-completion (CVE-2026-57456)
* vim: Vim: Out-of-bounds Write in Spell File Word Count (CVE-2026-55693)
* vim: Vim: Arbitrary code execution via crafted PHP file in omni-completion (CVE-2026-59856)
* vim: Vim: Arbitrary command execution via crafted tags file in C omni-completion (CVE-2026-59858)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
- CVE-2026-55693
- CVE-2026-57455
- CVE-2026-57456
- CVE-2026-59856
- CVE-2026-59858
- RHSA-2026:47982
- ALSA-2026:47982
Updated packages listed below:
| Architecture | Package | Checksum |
| aarch64 | vim-X11-8.2.2637-26.el9_8.13.aarch64.rpm | 024112d88f82bb62b0b2ce3dc64555dd19e4c68cd19ae557ffaeba3f737da14a |
| aarch64 | vim-common-8.2.2637-26.el9_8.13.aarch64.rpm | 52ebcf4480845be59d41c3b8d23d156fd432681f490d6c27adc8e78a4dce6d63 |
| aarch64 | vim-minimal-8.2.2637-26.el9_8.13.aarch64.rpm | 6574d1040686f3aa7caed487293dcfed3fbfd80cc61bf7c29be011088b83b6e5 |
| aarch64 | vim-enhanced-8.2.2637-26.el9_8.13.aarch64.rpm | c08444bee54e30fbbdd766d103976114fc17f5140e63a8b8eff1dc0b1fb51699 |
| noarch | vim-filesystem-8.2.2637-26.el9_8.13.noarch.rpm | 1dce4bf19fab1f7744521428e9e7318704d0264b3f6f15609608cbc8630aff78 |
| ppc64le | vim-common-8.2.2637-26.el9_8.13.ppc64le.rpm | 4907aeb9bd5ac28347cebc914373eaa9ec14a0e8a3e0adf94531a4a37670f237 |
| ppc64le | vim-enhanced-8.2.2637-26.el9_8.13.ppc64le.rpm | 604fa0d945b842b623df60ac841b0c07951daaa4f9d7bde131ff205f50c28e52 |
| ppc64le | vim-minimal-8.2.2637-26.el9_8.13.ppc64le.rpm | 6c970a621ca5afea37c854bce6e127c73f85904d1a95872e132bf0bb98da6950 |
| ppc64le | vim-X11-8.2.2637-26.el9_8.13.ppc64le.rpm | 9c7364a30fcf89c46e4d6e8662339ad1053126a91ce9b378dd0661cd23919bcb |
| s390x | vim-enhanced-8.2.2637-26.el9_8.13.s390x.rpm | 4960e3869c2f2cea000178ae4e00f1316c66bd563d41eb7a816180926bcd1245 |
| s390x | vim-minimal-8.2.2637-26.el9_8.13.s390x.rpm | 4bb5afb1d12444ba42f872f4edc68de107c2a0068ed964a91ce07580d036262f |
| s390x | vim-common-8.2.2637-26.el9_8.13.s390x.rpm | 4e6b843c6e24601821ba741abe58200566754d04fc06e27f34fa608e4cccd64e |
| s390x | vim-X11-8.2.2637-26.el9_8.13.s390x.rpm | c8be4a68f0a4a5b893d1007a31eb9eaedc9c7389fafddca58d6e6473101c7c31 |
| x86_64 | vim-minimal-8.2.2637-26.el9_8.13.x86_64.rpm | 18a72424b5b9cac5e27a824349c1d6dc5bc7f7967693fd02f08e6e85aa3aedf3 |
| x86_64 | vim-enhanced-8.2.2637-26.el9_8.13.x86_64.rpm | 1c840fd4bd75bf7d2656779bdbbe6736bff6ab6179a7df9eef016dc862d20141 |
| x86_64 | vim-X11-8.2.2637-26.el9_8.13.x86_64.rpm | 2ddf650f86b0ae9f8b232c38c46d9690e8372387b3123880203b6efa76fa44c6 |
| x86_64 | vim-common-8.2.2637-26.el9_8.13.x86_64.rpm | 3cd2655703e97072207e28c7a15aac407bc529f800458a49ca8652bbddbb857a |
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.
Источники
Предупреждения о безопасности
Похожие предупреждения
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему