Advisories ยป MGASA-2026-0355

Updated vim packages fix security vulnerabilities

Publication date: 01 Sep 2026
Modification date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-73077 , CVE-2026-73078 , CVE-2026-73074 , CVE-2026-73070 , CVE-2026-73075 , CVE-2026-73071 , CVE-2026-73073 , CVE-2026-73072 , CVE-2026-73076

Description

Arbitrary Code Execution via Shell Keyword Lookup in Vim < 9.2.0839.
(CVE-2026-73077)
Arbitrary Code Execution via Netrw Menu Construction in Vim < 9.2.0840.
(CVE-2026-73078)
Heap Buffer Overflow in Text Property Handling in Vim < 9.2.0841.
(CVE-2026-73074)
Stack Buffer Overflow in the Vim Socket Server in Vim < 9.2.0842.
(CVE-2026-73070)
Out-of-bounds Access in Popup Opacity Handling in Vim >= 9.2.0469 && Vim
< 9.2.0843. (CVE-2026-73075)
Use-after-free in JSON Decoding in Vim >= 9.2.0511 && Vim < 9.2.0844.
(CVE-2026-73071)
Arbitrary Ex Command Execution in C Omni-Completion in Vim < 9.2.0845.
(CVE-2026-73073)
Heap Buffer Overflow when Loading a Spell File in Vim < 9.2.0846.
(CVE-2026-73072)
Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay
in `vimball.vim`. (CVE-2026-73076)
                

References

SRPMS

10/core

9/core