Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6736 - Security Advisory
Issued:
2026-04-07
Updated:
2026-04-07

RHSA-2026:6736 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: vim security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for vim is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Vim (Vi IMproved) is an updated and improved version of the vi editor.

Security Fix(es):

  • vim: Vim: Arbitrary code execution via 'helpfile' option processing (CVE-2026-25749)
  • vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin (CVE-2026-28417)
  • vim: Vim: Denial of service and information disclosure via crafted swap file (CVE-2026-28421)
  • vim: Vim: Arbitrary code execution via command injection in glob() function (CVE-2026-33412)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2437843 - CVE-2026-25749 vim: Vim: Arbitrary code execution via 'helpfile' option processing
  • BZ - 2443455 - CVE-2026-28417 vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin
  • BZ - 2443474 - CVE-2026-28421 vim: Vim: Denial of service and information disclosure via crafted swap file
  • BZ - 2450907 - CVE-2026-33412 vim: Vim: Arbitrary code execution via command injection in glob() function

CVEs

  • CVE-2026-25749
  • CVE-2026-28417
  • CVE-2026-28421
  • CVE-2026-33412

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8

SRPM
vim-8.0.1763-20.el8_8.1.src.rpm SHA-256: 1ac260f9df5adf019a0c79381bf6b6396e9b5b1b7ba6faea18ad7982d51b2196
x86_64
vim-X11-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: f34752b49a3298565b53081921557506553572b6571e24907b40f20c70ee97ca
vim-X11-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d0604c372bcc661872efe8bd8bf24738b945b938aa85ad1e0a673892b1c9ff05
vim-X11-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d0604c372bcc661872efe8bd8bf24738b945b938aa85ad1e0a673892b1c9ff05
vim-common-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: a58f171701528d909a4f04930949af0024f4db98c12e0fb0d81f99eb2ed8eaa8
vim-common-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: e3eb75d3a039f72a80decd7eafd38c2762cfe84d81aac99d2ea2b4e2433ff1e2
vim-common-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: e3eb75d3a039f72a80decd7eafd38c2762cfe84d81aac99d2ea2b4e2433ff1e2
vim-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: cfe2c2fe477d98f2743699fc7e473fa75661a8e26d604ce76620c17b73c861af
vim-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: cfe2c2fe477d98f2743699fc7e473fa75661a8e26d604ce76620c17b73c861af
vim-debugsource-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d898a34525ec25df4eb7a37bd732e16f596b3450620d311b146c1acd329d8582
vim-debugsource-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d898a34525ec25df4eb7a37bd732e16f596b3450620d311b146c1acd329d8582
vim-enhanced-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 22261d2d67b18587ffbc717afcd3ddd484d110bb3392c69a4ed16c62015e6d34
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: c358623ee8f224e7ae59373adaf78742f39e22dd61fde432f913df27f8c4f499
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: c358623ee8f224e7ae59373adaf78742f39e22dd61fde432f913df27f8c4f499
vim-filesystem-8.0.1763-20.el8_8.1.noarch.rpm SHA-256: 730333fa4627f40f193c5c5f01f8b67330132545681875203bcef4917a63b6fd
vim-minimal-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 9ca5428cbb6416f0d5d8f4249723e44a7f0487b9835065b42567c3b468e1608c
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 756f996b686ff788a7314524320d015d6643caa6bc776bd4aaa061dc3fb8c6a8
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 756f996b686ff788a7314524320d015d6643caa6bc776bd4aaa061dc3fb8c6a8

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
vim-8.0.1763-20.el8_8.1.src.rpm SHA-256: 1ac260f9df5adf019a0c79381bf6b6396e9b5b1b7ba6faea18ad7982d51b2196
x86_64
vim-X11-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: f34752b49a3298565b53081921557506553572b6571e24907b40f20c70ee97ca
vim-X11-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d0604c372bcc661872efe8bd8bf24738b945b938aa85ad1e0a673892b1c9ff05
vim-X11-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d0604c372bcc661872efe8bd8bf24738b945b938aa85ad1e0a673892b1c9ff05
vim-common-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: a58f171701528d909a4f04930949af0024f4db98c12e0fb0d81f99eb2ed8eaa8
vim-common-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: e3eb75d3a039f72a80decd7eafd38c2762cfe84d81aac99d2ea2b4e2433ff1e2
vim-common-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: e3eb75d3a039f72a80decd7eafd38c2762cfe84d81aac99d2ea2b4e2433ff1e2
vim-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: cfe2c2fe477d98f2743699fc7e473fa75661a8e26d604ce76620c17b73c861af
vim-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: cfe2c2fe477d98f2743699fc7e473fa75661a8e26d604ce76620c17b73c861af
vim-debugsource-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d898a34525ec25df4eb7a37bd732e16f596b3450620d311b146c1acd329d8582
vim-debugsource-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d898a34525ec25df4eb7a37bd732e16f596b3450620d311b146c1acd329d8582
vim-enhanced-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 22261d2d67b18587ffbc717afcd3ddd484d110bb3392c69a4ed16c62015e6d34
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: c358623ee8f224e7ae59373adaf78742f39e22dd61fde432f913df27f8c4f499
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: c358623ee8f224e7ae59373adaf78742f39e22dd61fde432f913df27f8c4f499
vim-filesystem-8.0.1763-20.el8_8.1.noarch.rpm SHA-256: 730333fa4627f40f193c5c5f01f8b67330132545681875203bcef4917a63b6fd
vim-minimal-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 9ca5428cbb6416f0d5d8f4249723e44a7f0487b9835065b42567c3b468e1608c
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 756f996b686ff788a7314524320d015d6643caa6bc776bd4aaa061dc3fb8c6a8
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 756f996b686ff788a7314524320d015d6643caa6bc776bd4aaa061dc3fb8c6a8

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
vim-8.0.1763-20.el8_8.1.src.rpm SHA-256: 1ac260f9df5adf019a0c79381bf6b6396e9b5b1b7ba6faea18ad7982d51b2196
ppc64le
vim-X11-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 785d1c5be7bfb0bebaa4abbd6ec70420dcdcaedbec03eafc19047e36f52e69de
vim-X11-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 89cb1685ec5bd1b0a0241caa0eba3f94299b8ff5c0e69aca6bcba531608e0469
vim-X11-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 89cb1685ec5bd1b0a0241caa0eba3f94299b8ff5c0e69aca6bcba531608e0469
vim-common-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 1054a01e8aa94527038e9fcf7873ab6bf84dd53d7b908f07537a321f0c0f3ce1
vim-common-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 025ded22460a1fdcbd3dffe0ffd3e981ed8b4eacf5cef4ad0081bc7b7f3ac129
vim-common-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 025ded22460a1fdcbd3dffe0ffd3e981ed8b4eacf5cef4ad0081bc7b7f3ac129
vim-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: b25bbd0e4dd4d85c9440085995c593222d47b1e103eef46c3a669706c4a21671
vim-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: b25bbd0e4dd4d85c9440085995c593222d47b1e103eef46c3a669706c4a21671
vim-debugsource-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: f66231a999f66f1d862165fdfab1ec5f2a28a4aa54f35bef387789b4a73c0c27
vim-debugsource-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: f66231a999f66f1d862165fdfab1ec5f2a28a4aa54f35bef387789b4a73c0c27
vim-enhanced-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 1087551902de759a8711c4e59af4b38a704b95ce5e2f86d536f3b6d06fe5e0e3
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: f3ed4b44a62f01aceaa65d1483b7572f71c6ec53ba18c0476c59e562eb878ec3
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: f3ed4b44a62f01aceaa65d1483b7572f71c6ec53ba18c0476c59e562eb878ec3
vim-filesystem-8.0.1763-20.el8_8.1.noarch.rpm SHA-256: 730333fa4627f40f193c5c5f01f8b67330132545681875203bcef4917a63b6fd
vim-minimal-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: 70aa35c5955f7b0775260e47014300895fc6ce16f4f38625345ed58c4d00d4c3
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: be123061e21fb53903313220c7f04bf5cf8e8ee7523925a9f7ac7ea5f46bbfcf
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.ppc64le.rpm SHA-256: be123061e21fb53903313220c7f04bf5cf8e8ee7523925a9f7ac7ea5f46bbfcf

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
vim-8.0.1763-20.el8_8.1.src.rpm SHA-256: 1ac260f9df5adf019a0c79381bf6b6396e9b5b1b7ba6faea18ad7982d51b2196
x86_64
vim-X11-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: f34752b49a3298565b53081921557506553572b6571e24907b40f20c70ee97ca
vim-X11-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d0604c372bcc661872efe8bd8bf24738b945b938aa85ad1e0a673892b1c9ff05
vim-X11-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d0604c372bcc661872efe8bd8bf24738b945b938aa85ad1e0a673892b1c9ff05
vim-common-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: a58f171701528d909a4f04930949af0024f4db98c12e0fb0d81f99eb2ed8eaa8
vim-common-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: e3eb75d3a039f72a80decd7eafd38c2762cfe84d81aac99d2ea2b4e2433ff1e2
vim-common-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: e3eb75d3a039f72a80decd7eafd38c2762cfe84d81aac99d2ea2b4e2433ff1e2
vim-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: cfe2c2fe477d98f2743699fc7e473fa75661a8e26d604ce76620c17b73c861af
vim-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: cfe2c2fe477d98f2743699fc7e473fa75661a8e26d604ce76620c17b73c861af
vim-debugsource-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d898a34525ec25df4eb7a37bd732e16f596b3450620d311b146c1acd329d8582
vim-debugsource-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: d898a34525ec25df4eb7a37bd732e16f596b3450620d311b146c1acd329d8582
vim-enhanced-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 22261d2d67b18587ffbc717afcd3ddd484d110bb3392c69a4ed16c62015e6d34
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: c358623ee8f224e7ae59373adaf78742f39e22dd61fde432f913df27f8c4f499
vim-enhanced-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: c358623ee8f224e7ae59373adaf78742f39e22dd61fde432f913df27f8c4f499
vim-filesystem-8.0.1763-20.el8_8.1.noarch.rpm SHA-256: 730333fa4627f40f193c5c5f01f8b67330132545681875203bcef4917a63b6fd
vim-minimal-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 9ca5428cbb6416f0d5d8f4249723e44a7f0487b9835065b42567c3b468e1608c
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 756f996b686ff788a7314524320d015d6643caa6bc776bd4aaa061dc3fb8c6a8
vim-minimal-debuginfo-8.0.1763-20.el8_8.1.x86_64.rpm SHA-256: 756f996b686ff788a7314524320d015d6643caa6bc776bd4aaa061dc3fb8c6a8

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility