elsa-2026-22717

oracle_linux
Description

[8.2.2637-26.0.1.el9_8.5] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags [2:8.2.2637-26.1] - RHEL-159630 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-35177"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "[8.2.2637-26.0.1.el9_8.5]\n- Remove upstream references [Orabug: 31197557]\n\n[2:8.2.2637-26.5]\n- RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite\n  via path traversal bypass\n\n[2:8.2.2637-26.4]\n- Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass\n\n[2:8.2.2637-26.3]\n- Related: RHEL-159630 rebuild to build with exception target\n\n[2:8.2.2637-26.2]\n- remove -O0 from flags\n\n[2:8.2.2637-26.1]\n- RHEL-159630 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function",
  "id": "ELSA-2026-22717",
  "ovalId": "oval:com.oracle.elsa:def:202622717",
  "source": "oracle_linux",
  "title": "ELSA-2026-22717:  vim security update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-22717.html"
}
View JSON API Download JSON