Fedora Account System
Red Hat Associate
Red Hat Customer
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:66336 https://access.redhat.com/errata/RHSA-2026:66336
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:66366 https://access.redhat.com/errata/RHSA-2026:66366
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:70818 https://access.redhat.com/errata/RHSA-2026:70818
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:72466 https://access.redhat.com/errata/RHSA-2026:72466
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:72465 https://access.redhat.com/errata/RHSA-2026:72465