References: https://www.openwall.com/lists/oss-security/2026/03/19/10 https://github.com/vim/vim/security/advisories/GHSA-w5jw-f54h-x46c
Status comment: (none) => Fixed upstream in 9.2.202Whiteboard: (none) => MGA9TOOFlags: (none) => affects_mga9+CVE: (none) => CVE-2026-33412Source RPM: (none) => vim-9.2.140-1.mga10.src.rpm, vim-9.2.140-1.mga9.src.rpm
Assigning to our registered vim maintainer.
CC: (none) => marja11Assignee: bugsquad => thierry.vignaud
For Cauldron, I asked for a freeze move. Suggested advisory: ======================== The updated packages fix a security vulnerability: Command injection via newline in glob() affects Vim < 9.2.0202. (CVE-2026-33412) References: https://www.openwall.com/lists/oss-security/2026/03/19/10 https://github.com/vim/vim/security/advisories/GHSA-w5jw-f54h-x46c ======================== Updated packages in core/updates_testing: ======================== vim-X11-9.2.209-1.mga9 vim-common-9.2.209-1.mga9 vim-enhanced-9.2.209-1.mga9 vim-minimal-9.2.209-1.mga9 from SRPM: vim-9.2.209-1.mga9.src.rpm
Version: Cauldron => 9Flags: affects_mga9+ => (none)Status comment: Fixed upstream in 9.2.202 => (none)Source RPM: vim-9.2.140-1.mga10.src.rpm, vim-9.2.140-1.mga9.src.rpm => vim-9.2.140-1.mga9.src.rpmAssignee: thierry.vignaud => qa-bugsStatus: NEW => ASSIGNEDWhiteboard: MGA9TOO => (none)
MGA9-64 server Plasma Wayland on Compaq H000SB No installation issues. Tested by using the a, dd, i, x :wq commands. Checked with more, all works OK.
Flags: (none) => test_passed_mga9_64+Whiteboard: (none) => MGA9-64-OKCC: (none) => herman.viaene
Keywords: (none) => advisory
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0062.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED