Bug 2487964 (CVE-2026-47162)
| Summary: | CVE-2026-47162 vim: Vim: Arbitrary Code Execution via crafted directory names | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akhatavk, aos-team-art-private, asdas, dpaolell, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Vim, an open-source text editor. This vulnerability, located in the netrw plugin, involves a code injection issue when the editor processes directory paths. A malicious directory name, if crafted by an attacker, could bypass security measures and allow for the execution of unauthorized commands. This could lead to arbitrary code execution on the affected system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2491432 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-06-11 19:01:18 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:38509 https://access.redhat.com/errata/RHSA-2026:38509 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:38510 https://access.redhat.com/errata/RHSA-2026:38510 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:38511 https://access.redhat.com/errata/RHSA-2026:38511 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:55431 https://access.redhat.com/errata/RHSA-2026:55431 This issue has been addressed in the following products: Red Hat OpenShift Container Platform 4.22 Via RHSA-2026:54769 https://access.redhat.com/errata/RHSA-2026:54769 |