Executive brief
Vim, a widely used text editor for Linux and Unix-like systems, is vulnerable to a security bypass that allows a malicious file to execute commands on a user's computer. If a user opens a specially crafted text file, an attacker could gain the ability to run arbitrary programs, steal data, or modify files with the same permissions as the user. This occurs because certain editor settings, which are supposed to be restricted for security, can be manipulated through a feature called 'modelines'.
Technical details
A modeline sandbox bypass exists in Vim prior to version 9.2.0276. The 'complete', 'guitabtooltip', and 'printheader' options were missing the P_MLE flag, which is intended to prevent dangerous settings from being loaded via modelines. Furthermore, the mapset() function lacked a check_secure() call, allowing it to be invoked from sandboxed expressions to redefine key mappings and execute arbitrary code. An attacker can exploit this by providing a victim with a crafted file that, when opened, executes commands with the privileges of the Vim process. The issue is resolved in patch 9.2.0276.
Affected products
- Vim Vim < 9.2.0276
- Red Hat Red Hat Enterprise Linux 8, 9, 10
Timeline
- 2026-03-31: patched: Vim patch 9.2.0276 released
- 2026-03-31: advisory: GitHub Advisory GHSA-8h6p-m6gr-mpw9 published
- 2026-04-06: disclosed: CVE-2026-34982 published to NVD
References
- https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615
- https://github.com/vim/vim/releases/tag/v9.2.0276
- https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9
- http://www.openwall.com/lists/oss-security/2026/04/01/1
- https://access.redhat.com/errata/RHSA-2026:11389
- https://access.redhat.com/errata/RHSA-2026:11509
- https://access.redhat.com/errata/RHSA-2026:11510