Fedora Account System
Red Hat Associate
Red Hat Customer
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:28049 https://access.redhat.com/errata/RHSA-2026:28049
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:28050 https://access.redhat.com/errata/RHSA-2026:28050
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:28133 https://access.redhat.com/errata/RHSA-2026:28133
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:28210 https://access.redhat.com/errata/RHSA-2026:28210
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:28209 https://access.redhat.com/errata/RHSA-2026:28209
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:28553 https://access.redhat.com/errata/RHSA-2026:28553
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:30900 https://access.redhat.com/errata/RHSA-2026:30900
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:33453 https://access.redhat.com/errata/RHSA-2026:33453
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:34477 https://access.redhat.com/errata/RHSA-2026:34477
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:34476 https://access.redhat.com/errata/RHSA-2026:34476