Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6729 - Security Advisory
Issued:
2026-04-07
Updated:
2026-04-07

RHSA-2026:6729 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: vim security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for vim is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

  • vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749)
  • vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417)
  • vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421)
  • vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 8.4 x86_64

Fixes

  • BZ - 2437843 - CVE-2026-25749 vim: Vim: Arbitrary code execution via 'helpfile' option processing
  • BZ - 2443455 - CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
  • BZ - 2443474 - CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file
  • BZ - 2450907 - CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function

CVEs

  • CVE-2026-25749
  • CVE-2026-28417
  • CVE-2026-28421
  • CVE-2026-33412

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4

SRPM
vim-8.0.1763-15.el8_4.1.src.rpm SHA-256: 289d2c2a4588498aa803654d1ed20228c347c0a7114e1eb13cb426b6e275e5a7
x86_64
vim-X11-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bf433bc7dc6e6fd05c8149bf17b8c22b55cd518bfe9ab6ce1e9b70d60f7a25aa
vim-X11-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: aa6360a9bd602d5ed30ed5ce398548d0749f42acf01653fd5556103ee87a0a6a
vim-X11-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: aa6360a9bd602d5ed30ed5ce398548d0749f42acf01653fd5556103ee87a0a6a
vim-common-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: e5325b527eaf38fe6e2cc7fe2218f5d0cee7bf2ff147d7a6c2e4c5fc7c6059ae
vim-common-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bef1ba0761eea7c94da227fa038a0ae05ab64dbd65575b49e1d145a7a1af4354
vim-common-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bef1ba0761eea7c94da227fa038a0ae05ab64dbd65575b49e1d145a7a1af4354
vim-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bb6f2e011c86ca3b4e557ce794c74fd150062ab2b88f6858d84e9ff9c02f045a
vim-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bb6f2e011c86ca3b4e557ce794c74fd150062ab2b88f6858d84e9ff9c02f045a
vim-debugsource-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 670b32ab105405b572b339d67aee5a0cad3fec65f973630f9336f8bc97d3149e
vim-debugsource-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 670b32ab105405b572b339d67aee5a0cad3fec65f973630f9336f8bc97d3149e
vim-enhanced-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 246c94151eec1361c5eeca85fc6f53c2c17b83eeda1c8ddb911e9c4bb8236a4b
vim-enhanced-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 95b8add821e58e11b2765c5250e3b3947e6a63cb541dc429226c7fbbe764d7c3
vim-enhanced-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 95b8add821e58e11b2765c5250e3b3947e6a63cb541dc429226c7fbbe764d7c3
vim-filesystem-8.0.1763-15.el8_4.1.noarch.rpm SHA-256: 025bdafbad508d10d9c518fea350fccc9e112db8e1fae093fa184c06d88c9ab9
vim-minimal-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: c978caf7de409bdd670f52c6e570e9c7da03837917fb12282f197d376d83b1f7
vim-minimal-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: c9233bc084ecbe404b9d8c2b2b652b6735d94cf521f193c6d3486b9b272ef895
vim-minimal-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: c9233bc084ecbe404b9d8c2b2b652b6735d94cf521f193c6d3486b9b272ef895

Red Hat Enterprise Linux Server - AUS 8.4

SRPM
vim-8.0.1763-15.el8_4.1.src.rpm SHA-256: 289d2c2a4588498aa803654d1ed20228c347c0a7114e1eb13cb426b6e275e5a7
x86_64
vim-X11-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bf433bc7dc6e6fd05c8149bf17b8c22b55cd518bfe9ab6ce1e9b70d60f7a25aa
vim-X11-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: aa6360a9bd602d5ed30ed5ce398548d0749f42acf01653fd5556103ee87a0a6a
vim-X11-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: aa6360a9bd602d5ed30ed5ce398548d0749f42acf01653fd5556103ee87a0a6a
vim-common-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: e5325b527eaf38fe6e2cc7fe2218f5d0cee7bf2ff147d7a6c2e4c5fc7c6059ae
vim-common-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bef1ba0761eea7c94da227fa038a0ae05ab64dbd65575b49e1d145a7a1af4354
vim-common-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bef1ba0761eea7c94da227fa038a0ae05ab64dbd65575b49e1d145a7a1af4354
vim-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bb6f2e011c86ca3b4e557ce794c74fd150062ab2b88f6858d84e9ff9c02f045a
vim-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: bb6f2e011c86ca3b4e557ce794c74fd150062ab2b88f6858d84e9ff9c02f045a
vim-debugsource-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 670b32ab105405b572b339d67aee5a0cad3fec65f973630f9336f8bc97d3149e
vim-debugsource-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 670b32ab105405b572b339d67aee5a0cad3fec65f973630f9336f8bc97d3149e
vim-enhanced-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 246c94151eec1361c5eeca85fc6f53c2c17b83eeda1c8ddb911e9c4bb8236a4b
vim-enhanced-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 95b8add821e58e11b2765c5250e3b3947e6a63cb541dc429226c7fbbe764d7c3
vim-enhanced-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: 95b8add821e58e11b2765c5250e3b3947e6a63cb541dc429226c7fbbe764d7c3
vim-filesystem-8.0.1763-15.el8_4.1.noarch.rpm SHA-256: 025bdafbad508d10d9c518fea350fccc9e112db8e1fae093fa184c06d88c9ab9
vim-minimal-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: c978caf7de409bdd670f52c6e570e9c7da03837917fb12282f197d376d83b1f7
vim-minimal-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: c9233bc084ecbe404b9d8c2b2b652b6735d94cf521f193c6d3486b9b272ef895
vim-minimal-debuginfo-8.0.1763-15.el8_4.1.x86_64.rpm SHA-256: c9233bc084ecbe404b9d8c2b2b652b6735d94cf521f193c6d3486b9b272ef895

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility