elsa-2026-38511
oracle_linux[8.2.2637-26.0.1.el9_8.10] - Remove upstream references [Orabug: 31197557] [2:8.2.2637-26.10] - RHEL-186659 CVE-2026-47162 vim: code injection via NetrwBookHistSave() [2:8.2.2637-26.9] - RHEL-186646 CVE-2026-52858 vim: possible code execution with python3complete [2:8.2.2637-26.8] - RHEL-185874 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin [2:8.2.2637-26.7] - RHEL-178243 CVE-2026-46483 vim: command injection in tar plugin [2:8.2.2637-26.6] - CVE-2026-41411 vim: Command injection via backticks in tag files [2:8.2.2637-26.5] - RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite via path traversal bypass [2:8.2.2637-26.4] - Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass [2:8.2.2637-26.3] - Related: RHEL-159630 rebuild to build with exception target [2:8.2.2637-26.2] - remove -O0 from flags
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-46483",
"CVE-2026-47162",
"CVE-2026-47167",
"CVE-2026-52858"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[8.2.2637-26.0.1.el9_8.10]\n- Remove upstream references [Orabug: 31197557]\n\n[2:8.2.2637-26.10]\n- RHEL-186659 CVE-2026-47162 vim: code injection via\n NetrwBookHistSave()\n\n[2:8.2.2637-26.9]\n- RHEL-186646 CVE-2026-52858 vim: possible code execution with\n python3complete\n\n[2:8.2.2637-26.8]\n- RHEL-185874 CVE-2026-47167 vim: Code Injection in cucumber filetype plugin\n\n[2:8.2.2637-26.7]\n- RHEL-178243 CVE-2026-46483 vim: command injection in tar plugin\n\n[2:8.2.2637-26.6]\n- CVE-2026-41411 vim: Command injection via backticks in tag files\n\n[2:8.2.2637-26.5]\n- RHEL-170136 CVE-2026-35177 vim: Vim zip.vim plugin: Arbitrary file overwrite\n via path traversal bypass\n\n[2:8.2.2637-26.4]\n- Resolves: RHEL-164966 vim: arbitrary command execution via modeline sandbox bypass\n\n[2:8.2.2637-26.3]\n- Related: RHEL-159630 rebuild to build with exception target\n\n[2:8.2.2637-26.2]\n- remove -O0 from flags",
"id": "ELSA-2026-38511",
"ovalId": "oval:com.oracle.elsa:def:202638511",
"source": "oracle_linux",
"title": "ELSA-2026-38511: vim security update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-38511.html"
}