References: https://www.openwall.com/lists/oss-security/2026/04/07/13 https://github.com/vim/vim/security/advisories/GHSA-mr87-rhgv-7pw6
Status comment: (none) => Fixed upstream in 9.2.316Source RPM: (none) => vim-9.2.280-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpmFlags: (none) => affects_mga9+Whiteboard: (none) => MGA9TOOCVE: (none) => CVE-2026-39881
For Cauldron, I asked for a freeze move.
Version: Cauldron => 9Source RPM: vim-9.2.280-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm => vim-9.2.280-1.mga9.src.rpmWhiteboard: MGA9TOO => (none)Flags: affects_mga9+ => (none)
Cauldron done, just M9 to do.
Assignee: bugsquad => pkg-bugs
References: https://www.openwall.com/lists/oss-security/2026/04/15/7 https://github.com/vim/vim/security/advisories/GHSA-cwgx-gcj7-6qh8
Source RPM: vim-9.2.280-1.mga9.src.rpm => vim-9.2.329-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpmFlags: (none) => affects_mga9+Whiteboard: (none) => MGA9TOOVersion: 9 => Cauldron
Status comment: Fixed upstream in 9.2.316 => Fixed upstream in 9.2.357Whiteboard: MGA9TOO => (none)Flags: affects_mga9+ => (none)Source RPM: vim-9.2.329-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm => vim-9.2.280-1.mga9.src.rpmVersion: Cauldron => 9
References: https://www.openwall.com/lists/oss-security/2026/04/22/8 https://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx (no CVE yet)
Status comment: Fixed upstream in 9.2.357 => Fixed upstream in 9.2.383Version: 9 => CauldronCVE: CVE-2026-39881 => CVE-2026-39881, CVE-2026-41411Summary: vim new security issue CVE-2026-39881 => vim new security issue CVE-2026-39881, CVE-2026-41411Flags: (none) => affects_mga9+Source RPM: vim-9.2.280-1.mga9.src.rpm => vim-9.2.357-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpmWhiteboard: (none) => MGA9TOO
CVE-2026-42307 was assigned for the issue from comment 5.
Summary: vim new security issue CVE-2026-39881, CVE-2026-41411 => vim new security issue CVE-2026-39881, CVE-2026-41411, CVE-2026-42307CVE: CVE-2026-39881, CVE-2026-41411 => CVE-2026-39881, CVE-2026-41411, CVE-2026-42307
References: https://www.openwall.com/lists/oss-security/2026/05/03/11 https://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg (no CVE yet)
Summary: vim new security issue CVE-2026-39881, CVE-2026-41411, CVE-2026-42307 => vim new security issues CVE-2026-39881, CVE-2026-41411, CVE-2026-42307Status comment: Fixed upstream in 9.2.383 => Fixed upstream in 9.2.435
Source RPM: vim-9.2.357-1.mga10.src.rpm, vim-9.2.280-1.mga9.src.rpm => vim-9.2.280-1.mga9.src.rpmVersion: Cauldron => 9Flags: affects_mga9+ => (none)Whiteboard: MGA9TOO => (none)
Suggested advisory: ======================== The updated packages fix security vulnerabilities: Ex command injection in Vims NetBeans integration. (CVE-2026-39881) Command injection via backtick expansion in tag filenames in Vim < v9.2.0357. (CVE-2026-41411) OS Command Injection in netrw affects Vim < 9.2.0383. (CVE-2026-42307) OS Command Injection via 'path' completion affects Vim < 9.2.0435. References: https://www.openwall.com/lists/oss-security/2026/04/07/13 https://github.com/vim/vim/security/advisories/GHSA-mr87-rhgv-7pw6 https://www.openwall.com/lists/oss-security/2026/04/15/7 https://github.com/vim/vim/security/advisories/GHSA-cwgx-gcj7-6qh8 https://www.openwall.com/lists/oss-security/2026/04/22/8 https://github.com/vim/vim/security/advisories/GHSA-85ch-p2qr-m5gx https://www.openwall.com/lists/oss-security/2026/05/03/11 https://github.com/vim/vim/security/advisories/GHSA-hwg5-3cxw-wvvg ======================== Updated packages in core/updates_testing: ======================== vim-X11-9.2.437-1.mga9 vim-common-9.2.437-1.mga9 vim-enhanced-9.2.437-1.mga9 vim-minimal-9.2.437-1.mga9 from SRPM: vim-9.2.437-1.mga9.src.rpm
Assignee: pkg-bugs => qa-bugsStatus comment: Fixed upstream in 9.2.435 => (none)Status: NEW => ASSIGNED
Keywords: (none) => advisory
MGA9-64 server Plasma Wayland on Compaq H000SB No isntallation issues. Exercised commands, a, dd, i, :wq, all OK.
CC: (none) => herman.viaeneFlags: (none) => test_passed_mga9_64+Whiteboard: (none) => MGA9-64-OK
CC: (none) => andrewsfarm
Blocks: (none) => 35490
Validating.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0123.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED