elsa-2026-38510
oracle_linux
Description
[8.0.1763-27.0.1] - Remove upstream references [Orabug: 31197557] - Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984] [2:8.0.1763-27] - RHEL-186656 CVE-2026-47162 vim: netrw code injection via NetrwBookHistSave - RHEL-186648 CVE-2026-52858 vim: possible code execution with python3complete [2:8.0.1763-26] - CVE-2026-47167 vim: Code Injection in cucumber filetype plugin [2:8.0.1763-25] - RHEL-178234 CVE-2026-46483 vim: command injection in tar plugin via shellescape
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-46483",
"CVE-2026-47162",
"CVE-2026-47167",
"CVE-2026-52858"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[8.0.1763-27.0.1]\n- Remove upstream references [Orabug: 31197557]\n- Added glibc-gconv-extra to common requires to provide ISO-8859-2 [Orabug: 34114984]\n\n[2:8.0.1763-27]\n- RHEL-186656 CVE-2026-47162 vim: netrw code injection via NetrwBookHistSave\n- RHEL-186648 CVE-2026-52858 vim: possible code execution with python3complete\n\n[2:8.0.1763-26]\n- CVE-2026-47167 vim: Code Injection in cucumber filetype plugin\n\n[2:8.0.1763-25]\n- RHEL-178234 CVE-2026-46483 vim: command injection in tar plugin via\n shellescape",
"id": "ELSA-2026-38510",
"ovalId": "oval:com.oracle.elsa:def:202638510",
"source": "oracle_linux",
"title": "ELSA-2026-38510: vim security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-38510.html"
}