|
|
Log in / Subscribe / Register

Ubuntu alert USN-8500-1 (vim)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8500-1] Vim vulnerabilities
Date:  Thu, 02 Jul 2026 18:52:51 +0000
Message-ID:  <E1wfMWp-0000Dn-TS@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8500-1 July 02, 2026 vim vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Vim. Software Description: - vim: Vi IMproved - enhanced vi editor Details: It was discovered that Vim incorrectly handled path traversal in the zip.vim plugin. An attacker could possibly use this issue to overwrite arbitrary files. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-35177) It was discovered that Vim incorrectly handled depth tracking when processing spell files. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-55693, CVE-2026-55892) It was discovered that Vim incorrectly handled filename escaping in the netrw plugin. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-55895) It was discovered that Vim incorrectly handled length calculations when opening encrypted files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-57452) Dhruv Vishesh Gupta discovered that Vim incorrectly handled quoting of archive entry names. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-57453) It was discovered that Vim incorrectly handled bounds checking when translating words through a byte map. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-57455) Chenyuan Mi discovered that Vim incorrectly handled docstring escaping during Python omni-completion. An attacker could possibly use this issue to execute arbitrary code. (CVE-2026-57456) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS vim 2:9.1.2141-1ubuntu4.6 vim-common 2:9.1.2141-1ubuntu4.6 vim-gtk3 2:9.1.2141-1ubuntu4.6 vim-gui-common 2:9.1.2141-1ubuntu4.6 vim-motif 2:9.1.2141-1ubuntu4.6 vim-nox 2:9.1.2141-1ubuntu4.6 vim-runtime 2:9.1.2141-1ubuntu4.6 vim-tiny 2:9.1.2141-1ubuntu4.6 xxd 2:9.1.2141-1ubuntu4.6 Ubuntu 25.10 vim 2:9.1.0967-1ubuntu6.8 vim-athena 2:9.1.0967-1ubuntu6.8 vim-common 2:9.1.0967-1ubuntu6.8 vim-gtk3 2:9.1.0967-1ubuntu6.8 vim-gui-common 2:9.1.0967-1ubuntu6.8 vim-motif 2:9.1.0967-1ubuntu6.8 vim-nox 2:9.1.0967-1ubuntu6.8 vim-runtime 2:9.1.0967-1ubuntu6.8 vim-tiny 2:9.1.0967-1ubuntu6.8 xxd 2:9.1.0967-1ubuntu6.8 Ubuntu 24.04 LTS vim 2:9.1.0016-1ubuntu7.17 vim-athena 2:9.1.0016-1ubuntu7.17 vim-common 2:9.1.0016-1ubuntu7.17 vim-gtk3 2:9.1.0016-1ubuntu7.17 vim-gui-common 2:9.1.0016-1ubuntu7.17 vim-motif 2:9.1.0016-1ubuntu7.17 vim-nox 2:9.1.0016-1ubuntu7.17 vim-runtime 2:9.1.0016-1ubuntu7.17 vim-tiny 2:9.1.0016-1ubuntu7.17 xxd 2:9.1.0016-1ubuntu7.17 Ubuntu 22.04 LTS vim 2:8.2.3995-1ubuntu2.33 vim-athena 2:8.2.3995-1ubuntu2.33 vim-common 2:8.2.3995-1ubuntu2.33 vim-gtk 2:8.2.3995-1ubuntu2.33 vim-gtk3 2:8.2.3995-1ubuntu2.33 vim-gui-common 2:8.2.3995-1ubuntu2.33 vim-nox 2:8.2.3995-1ubuntu2.33 vim-runtime 2:8.2.3995-1ubuntu2.33 vim-tiny 2:8.2.3995-1ubuntu2.33 xxd 2:8.2.3995-1ubuntu2.33 Ubuntu 20.04 LTS vim 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-athena 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-common 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-gtk 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-gtk3 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-gui-common 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-nox 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-runtime 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro vim-tiny 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro xxd 2:8.1.2269-1ubuntu5.32+esm9 Available with Ubuntu Pro Ubuntu 18.04 LTS vim 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-athena 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-common 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-gnome 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-gtk 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-gtk3 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-gui-common 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-nox 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-runtime 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro vim-tiny 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro xxd 2:8.0.1453-1ubuntu1.13+esm21 Available with Ubuntu Pro Ubuntu 16.04 LTS vim 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-athena 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-athena-py2 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-common 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-gnome 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-gnome-py2 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-gtk 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-gtk-py2 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-gtk3 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-gtk3-py2 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-gui-common 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-nox 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-nox-py2 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-runtime 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro vim-tiny 2:7.4.1689-3ubuntu1.5+esm36 Available with Ubuntu Pro Ubuntu 14.04 LTS vim 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-athena 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-common 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-gnome 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-gtk 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-gui-common 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-lesstif 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-nox 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-runtime 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro vim-tiny 2:7.4.052-1ubuntu3.1+esm30 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8500-1 CVE-2026-35177, CVE-2026-55693, CVE-2026-55892, CVE-2026-55895, CVE-2026-57452, CVE-2026-57453, CVE-2026-57455, CVE-2026-57456 Package Information: https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubun... https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubun... https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubun... https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubun...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpGspsACgkQcpJm3tlz hgHLmw/9FKzz9cNXmx/dnmyXrLzOMXKUNTazTe+QxQLkP7dR0J1nqvpCRWx/SYPZ jvEEu9Rpm++6lSfR1T5iaTRUV6cBdPnjzDwQbA8p/y1qD658VB1xH38+d9zdb7cA FY1w7yKgBIC5+0FNtcTSocB9qacNXXvvRTSuUWlbq5orP7jrkeE/+smI148hgQC+ cECziO4bIAxpzwzoPFoPAHF6DENcl6U2O3Ofxvihm9/Jgy3cbnMLPrcmP6nh/oAl SP5yVVGVNmv94657KI/WlJ9NsDXOIFFi476rNRRHqEQKcSc4xrIEnELLX7O3iggO f+SxfWMS2tXUuab4jNzHYanERm7DrWD+aaLJCIqki2+hpn5d5wkAtdh4TLh6DXpA o0fMJbiXifP280JlVp60DThgKi4+Bu5YHip37jD0JE4+k3OP0Kw7A08kIAdAOs3Q gVjyq8erND1tnPVOe1AoYxwa88ALp+QZbNYLx3OvLHEFU+pl+p518d5RrLGKS3z3 KuUumobxknMZr3f40R+aFi1IuD1SqzL5GDH0RJBYKCZwvXx6CfIty74OiQEFANL0 SlJ6z2Cgw0ES86kzM/n/F6WAPDnagSHzMZAy5SYiUEUpNnapRPMi53uJSaPJjpY0 O/dLXvWRAivypGMyRBGyYJ7IqdFSaEKU+nlZQy0ponxKXG+os28= =BQA+ -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds