Bug 35332 - vim new security issues CVE-2026-39881, CVE-2026-41411, CVE-2026-42307
Summary: vim new security issues CVE-2026-39881, CVE-2026-41411, CVE-2026-42307
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 35490
  Show dependency treegraph
 
Reported: 2026-04-08 15:49 CEST by Nicolas Salguero
Modified: 2026-05-09 18:25 CEST (History)
3 users (show)

See Also:
Source RPM: vim-9.2.280-1.mga9.src.rpm
CVE: CVE-2026-39881, CVE-2026-41411, CVE-2026-42307
Status comment:
herman.viaene: test_passed_mga9_64+


Attachments

Nicolas Salguero 2026-04-08 15:50:58 CEST

Status comment: (none) => Fixed upstream in 9.2.316
Source RPM: (none) => vim-9.2.280-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm
Flags: (none) => affects_mga9+
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2026-39881

Comment 1 Nicolas Salguero 2026-04-10 10:39:31 CEST
For Cauldron, I asked for a freeze move.

Version: Cauldron => 9
Source RPM: vim-9.2.280-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm => vim-9.2.280-1.mga9.src.rpm
Whiteboard: MGA9TOO => (none)
Flags: affects_mga9+ => (none)

Comment 2 Lewis Smith 2026-04-14 21:35:41 CEST
Cauldron done, just M9 to do.

Assignee: bugsquad => pkg-bugs

Comment 3 Nicolas Salguero 2026-04-16 11:05:04 CEST
References:
https://www.openwall.com/lists/oss-security/2026/04/15/7
https://github.com/vim/vim/security/advisories/GHSA-cwgx-gcj7-6qh8

Source RPM: vim-9.2.280-1.mga9.src.rpm => vim-9.2.329-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm
Flags: (none) => affects_mga9+
Whiteboard: (none) => MGA9TOO
Version: 9 => Cauldron

Comment 4 Nicolas Salguero 2026-04-16 11:45:34 CEST
For Cauldron, I asked for a freeze move.

Status comment: Fixed upstream in 9.2.316 => Fixed upstream in 9.2.357
Whiteboard: MGA9TOO => (none)
Flags: affects_mga9+ => (none)
Source RPM: vim-9.2.329-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm => vim-9.2.280-1.mga9.src.rpm
Version: Cauldron => 9

Comment 5 Nicolas Salguero 2026-04-27 14:12:43 CEST
References:
https://www.openwall.com/lists/oss-security/2026/04/22/8
https://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx (no CVE yet)

Status comment: Fixed upstream in 9.2.357 => Fixed upstream in 9.2.383
Version: 9 => Cauldron
CVE: CVE-2026-39881 => CVE-2026-39881, CVE-2026-41411
Summary: vim new security issue CVE-2026-39881 => vim new security issue CVE-2026-39881, CVE-2026-41411
Flags: (none) => affects_mga9+
Source RPM: vim-9.2.280-1.mga9.src.rpm => vim-9.2.357-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 6 Nicolas Salguero 2026-04-28 10:15:28 CEST
CVE-2026-42307 was assigned for the issue from comment 5.

Summary: vim new security issue CVE-2026-39881, CVE-2026-41411 => vim new security issue CVE-2026-39881, CVE-2026-41411, CVE-2026-42307
CVE: CVE-2026-39881, CVE-2026-41411 => CVE-2026-39881, CVE-2026-41411, CVE-2026-42307

Comment 7 Nicolas Salguero 2026-05-04 11:16:49 CEST
References:
https://www.openwall.com/lists/oss-security/2026/05/03/11
https://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg (no CVE yet)

Summary: vim new security issue CVE-2026-39881, CVE-2026-41411, CVE-2026-42307 => vim new security issues CVE-2026-39881, CVE-2026-41411, CVE-2026-42307
Status comment: Fixed upstream in 9.2.383 => Fixed upstream in 9.2.435

Comment 8 Nicolas Salguero 2026-05-04 13:09:23 CEST
For Cauldron, I asked for a freeze move.

Source RPM: vim-9.2.357-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm => vim-9.2.280-1.mga9.src.rpm
Version: Cauldron => 9
Flags: affects_mga9+ => (none)
Whiteboard: MGA9TOO => (none)

Comment 9 Nicolas Salguero 2026-05-04 13:34:56 CEST
Suggested advisory:
========================

The updated packages fix security vulnerabilities:

Ex command injection in Vims NetBeans integration. (CVE-2026-39881)

Command injection via backtick expansion in tag filenames in Vim < v9.2.0357. (CVE-2026-41411)

OS Command Injection in netrw affects Vim < 9.2.0383. (CVE-2026-42307)

OS Command Injection via 'path' completion affects Vim < 9.2.0435.

References:
https://www.openwall.com/lists/oss-security/2026/04/07/13
https://github.com/vim/vim/security/advisories/GHSA-mr87-rhgv-7pw6
https://www.openwall.com/lists/oss-security/2026/04/15/7
https://github.com/vim/vim/security/advisories/GHSA-cwgx-gcj7-6qh8
https://www.openwall.com/lists/oss-security/2026/04/22/8
https://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx
https://www.openwall.com/lists/oss-security/2026/05/03/11
https://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg
========================

Updated packages in core/updates_testing:
========================
vim-X11-9.2.437-1.mga9
vim-common-9.2.437-1.mga9
vim-enhanced-9.2.437-1.mga9
vim-minimal-9.2.437-1.mga9

from SRPM:
vim-9.2.437-1.mga9.src.rpm

Assignee: pkg-bugs => qa-bugs
Status comment: Fixed upstream in 9.2.435 => (none)
Status: NEW => ASSIGNED

katnatek 2026-05-07 04:32:20 CEST

Keywords: (none) => advisory

Comment 10 Herman Viaene 2026-05-07 11:45:08 CEST
MGA9-64 server Plasma Wayland on Compaq H000SB
No isntallation issues.
Exercised commands, a, dd, i, :wq, all OK.

CC: (none) => herman.viaene
Flags: (none) => test_passed_mga9_64+
Whiteboard: (none) => MGA9-64-OK

katnatek 2026-05-09 01:04:16 CEST

CC: (none) => andrewsfarm

Nicolas Salguero 2026-05-09 11:48:04 CEST

Blocks: (none) => 35490

Comment 11 Thomas Andrews 2026-05-09 17:01:06 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 12 Mageia Robot 2026-05-09 18:25:26 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0123.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.