elsa-2026-22730

oracle_linux
Description

[8.0.1763-23.0.1] - Remove upstream references [Orabug: 31197557] - Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984] [2:8.0.1763-23] - RHEL-170126 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.0.1763-22.3] - Relates: RHEL-164956 vim: arbitrary command execution via modeline sandbox bypass [2:8.0.1763-22.2] - Resolves: RHEL-164956 vim: arbitrary command execution via modeline sandbox bypass [2:8.0.1763-22.1] - RHEL-159620 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function - RHEL-155428 CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin - RHEL-155412 CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-35177"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "[8.0.1763-23.0.1]\n- Remove upstream references [Orabug: 31197557]\n- Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984]\n\n[2:8.0.1763-23]\n- RHEL-170126 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite\n  via path traversal bypass\n\n[2:8.0.1763-22.3]\n- Relates: RHEL-164956 vim: arbitrary command execution via modeline sandbox bypass\n\n[2:8.0.1763-22.2]\n- Resolves: RHEL-164956 vim: arbitrary command execution via modeline sandbox bypass\n\n[2:8.0.1763-22.1]\n- RHEL-159620 CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function\n- RHEL-155428 CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin\n- RHEL-155412 CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file",
  "id": "ELSA-2026-22730",
  "ovalId": "oval:com.oracle.elsa:def:202622730",
  "source": "oracle_linux",
  "title": "ELSA-2026-22730:  vim security update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-22730.html"
}
View JSON API Download JSON