Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6619 - Security Advisory
Issued:
2026-04-06
Updated:
2026-04-06

RHSA-2026:6619 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: vim security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for vim is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

  • vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749)
  • vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417)
  • vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421)
  • vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2437843 - CVE-2026-25749 vim: Vim: Arbitrary code execution via 'helpfile' option processing
  • BZ - 2443455 - CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
  • BZ - 2443474 - CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file
  • BZ - 2450907 - CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function

CVEs

  • CVE-2026-25749
  • CVE-2026-28417
  • CVE-2026-28421
  • CVE-2026-33412

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
vim-8.2.2637-16.el9_0.4.src.rpm SHA-256: 7b5365f0ede96cd7646bac895ce2d306ed74d2763989336028b7a4a1fa93cca0
ppc64le
vim-X11-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: a13750756188c569d5ad1ebf8ee71ed008d535eccfc3791ce2ea7dfafcf321f0
vim-X11-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: ef28cbdb9cca77b08eef97241040d94b353690bc50a5e7a233df26f2712a8ac5
vim-X11-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: ef28cbdb9cca77b08eef97241040d94b353690bc50a5e7a233df26f2712a8ac5
vim-common-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: 13256a71e35de63f65024ddfec103d60e8ccf7d0c86184f140e31f5c0bad6362
vim-common-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: f2d735e47232085d06d96b6ab70feab36614c209585ac62548352c01c7735409
vim-common-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: f2d735e47232085d06d96b6ab70feab36614c209585ac62548352c01c7735409
vim-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: cf06a511bd8581831984e8cbe4453ea8cd138b0fa959409c7e5e6d9b7caf2e15
vim-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: cf06a511bd8581831984e8cbe4453ea8cd138b0fa959409c7e5e6d9b7caf2e15
vim-debugsource-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: 044767b8720275a80dd2ede5e9a2a29003afd003e0f802e9fc68d320bc7bcb28
vim-debugsource-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: 044767b8720275a80dd2ede5e9a2a29003afd003e0f802e9fc68d320bc7bcb28
vim-enhanced-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: 455a639a70cba341a93114414b60aebb095ed965ab57c8c2df462bbff26316dd
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: e854338cc110e978969135dae403d15fb2a011326438548977b35a9734551d80
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: e854338cc110e978969135dae403d15fb2a011326438548977b35a9734551d80
vim-filesystem-8.2.2637-16.el9_0.4.noarch.rpm SHA-256: 98ee2337cd4e4a475f2b0446d0a6a7a14b40ba0be437d09bce1897ba9a134e3b
vim-minimal-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: fb0255316f3ffe95bafc3019297540ca45ca3b1dea94209baaba19f5477a1c93
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: 8eefae738af74a323b37bbea3f6ce3b731472b2cc5a519a54f2e050b0dd7db76
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.ppc64le.rpm SHA-256: 8eefae738af74a323b37bbea3f6ce3b731472b2cc5a519a54f2e050b0dd7db76

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
vim-8.2.2637-16.el9_0.4.src.rpm SHA-256: 7b5365f0ede96cd7646bac895ce2d306ed74d2763989336028b7a4a1fa93cca0
x86_64
vim-X11-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 71f8e9613f56ca37a22925b7c31555805ac0e330d3e38b380b9c1054214a77ba
vim-X11-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 64144815f061ff9fab3d7a5cd98837f8aa911d85776ee1bccbfa40741e1a4d29
vim-X11-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 64144815f061ff9fab3d7a5cd98837f8aa911d85776ee1bccbfa40741e1a4d29
vim-common-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 132686284b65e70676e99908d27c04f1ed787f45f45c0ec02896ebe210d50918
vim-common-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 564394e53527b9eac0bcf91533856a17cc6f567788c649a06c2e29bfc27f3973
vim-common-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 564394e53527b9eac0bcf91533856a17cc6f567788c649a06c2e29bfc27f3973
vim-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 14d2ae17d59084f38490efe9a51b97df0c00f00a22b1a9b842d5c4d217ac717e
vim-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 14d2ae17d59084f38490efe9a51b97df0c00f00a22b1a9b842d5c4d217ac717e
vim-debugsource-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 09e9f128c1a4e7fa8141d95c51e065a4695fec9597881da8ecf83a163bf3793b
vim-debugsource-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 09e9f128c1a4e7fa8141d95c51e065a4695fec9597881da8ecf83a163bf3793b
vim-enhanced-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 7e8f6a86f1c5c4b4e8ba57a0ece5e60e4c09de26c8e1f42a54687f2d02f290db
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 723fd21bbf0c93f9d85940b0eb0cdeaae9f5c91e7786c16fa0e412a7000cba14
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 723fd21bbf0c93f9d85940b0eb0cdeaae9f5c91e7786c16fa0e412a7000cba14
vim-filesystem-8.2.2637-16.el9_0.4.noarch.rpm SHA-256: 98ee2337cd4e4a475f2b0446d0a6a7a14b40ba0be437d09bce1897ba9a134e3b
vim-minimal-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 4d5cf4bef6cdcce21b3c29eed3517de61a057cb0f683c4d910dde4227360f686
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 8117e3e05c913a2313485a5092f86fa50ebd1f32060588a6145ecf0bbb22118f
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.x86_64.rpm SHA-256: 8117e3e05c913a2313485a5092f86fa50ebd1f32060588a6145ecf0bbb22118f

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
vim-8.2.2637-16.el9_0.4.src.rpm SHA-256: 7b5365f0ede96cd7646bac895ce2d306ed74d2763989336028b7a4a1fa93cca0
aarch64
vim-X11-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 7bc4446de54b46d21c492a825cb94b070347f1e722669641d944311d2aa1aca5
vim-X11-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: f2cc7a39de37564349c01b7f7ac8e1ec834641250482bdd800ceb09ae919f983
vim-X11-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: f2cc7a39de37564349c01b7f7ac8e1ec834641250482bdd800ceb09ae919f983
vim-common-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 4e744175492b7b98adf828b3c3e3cdddf24927a1c1d6678b934ace0745eadc5a
vim-common-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 1f3535e5d33cb9a23e1fcc1e84cf39eebaa39f23ff4111d4369b13b7ca1ea3d0
vim-common-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 1f3535e5d33cb9a23e1fcc1e84cf39eebaa39f23ff4111d4369b13b7ca1ea3d0
vim-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: c6bebb444c6e9384ddb72c8612ebb6cc4d4fd3e7a97ac24e8b04dd28f1d45169
vim-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: c6bebb444c6e9384ddb72c8612ebb6cc4d4fd3e7a97ac24e8b04dd28f1d45169
vim-debugsource-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: c27d9ebac27bc3a8a410afb61991580890b3517e40da91522e2c9397288a9a8d
vim-debugsource-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: c27d9ebac27bc3a8a410afb61991580890b3517e40da91522e2c9397288a9a8d
vim-enhanced-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 8e59a91ee9f562b08e847d3877f68cf17b688f025dcf70ddb280247bb6dd06ce
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 5a71945ff98c4acf96e1e37b9d42952e7583141c065f47ed35847c47b4b59c44
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 5a71945ff98c4acf96e1e37b9d42952e7583141c065f47ed35847c47b4b59c44
vim-filesystem-8.2.2637-16.el9_0.4.noarch.rpm SHA-256: 98ee2337cd4e4a475f2b0446d0a6a7a14b40ba0be437d09bce1897ba9a134e3b
vim-minimal-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 09c2b466ad1c9c246935156b07e990e226ff5ae32c4cf255342e1e6369ff9468
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 8b7556a158e4eda62bb0f81b2a6dcfe9bb5552a1282b7885e472618b51716b74
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.aarch64.rpm SHA-256: 8b7556a158e4eda62bb0f81b2a6dcfe9bb5552a1282b7885e472618b51716b74

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
vim-8.2.2637-16.el9_0.4.src.rpm SHA-256: 7b5365f0ede96cd7646bac895ce2d306ed74d2763989336028b7a4a1fa93cca0
s390x
vim-X11-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 2e5c0961008b85021b8d42dbd39abb94fbe0951f42eda72a9a3624b3c21004d8
vim-X11-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: be44d30c39d3cf92adf19bc8432bc65c5322b32f157e634696cd9cd388e38eb5
vim-X11-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: be44d30c39d3cf92adf19bc8432bc65c5322b32f157e634696cd9cd388e38eb5
vim-common-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: b639680048cef906490500ce8c97dd795e7e1401a0dac12abe0c93df3f343639
vim-common-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 32b3ca9dee64a7469011984da8b1328813ce35b176713497672eb123e1f8d902
vim-common-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 32b3ca9dee64a7469011984da8b1328813ce35b176713497672eb123e1f8d902
vim-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 3cd9051023aa3bdcfaf01c27ecd5735f308595544c2e641e137b830e181535f1
vim-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 3cd9051023aa3bdcfaf01c27ecd5735f308595544c2e641e137b830e181535f1
vim-debugsource-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 54c1ad00096a3f32521c73a2916472bcfc8e517eef628f39bfb354288487ab5d
vim-debugsource-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 54c1ad00096a3f32521c73a2916472bcfc8e517eef628f39bfb354288487ab5d
vim-enhanced-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: f627b732790516cbf73f52cceb2e6d2b28115b081542c76329a43a3565ac2ed4
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: e350827f4023a4d2e40a930adedb56836bf24b976719f1fb50b639e502d13876
vim-enhanced-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: e350827f4023a4d2e40a930adedb56836bf24b976719f1fb50b639e502d13876
vim-filesystem-8.2.2637-16.el9_0.4.noarch.rpm SHA-256: 98ee2337cd4e4a475f2b0446d0a6a7a14b40ba0be437d09bce1897ba9a134e3b
vim-minimal-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 9645190cf017b6ad87446da5357f0efb91942ecd29904a440e9c97506673578d
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 7b6724ff0e97808344edd0838dd62166ae4a90888a0bfbe959215db0c4649e9a
vim-minimal-debuginfo-8.2.2637-16.el9_0.4.s390x.rpm SHA-256: 7b6724ff0e97808344edd0838dd62166ae4a90888a0bfbe959215db0c4649e9a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility