CVE-2026-34982

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)

Beschreibung

Vim ist ein quelloffenes Texteditor für die Kommandozeile. Vor Version 9.2.0276 ermöglicht eine Umgehung der Sandkastensicherung in Vim die Ausführung beliebiger Betriebssystembefehle, wenn ein Benutzer eine manipulierte Datei öffnet. Die Optionen `complete`, `guitabtooltip` und `printheader` fehlt die `P_MLE`-Flagge, was es ermöglicht, dass eine Modeline ausgeführt wird. Darüber hinaus fehlt der Funktion `mapset()` ein Aufruf von `check_secure()`, wodurch sie aus sandkastengeschützten Ausdrücken missbraucht werden kann. Der Commit 9.2.0276 behebt das Problem.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.2
Quelle: nvd-v3
39.2 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.5 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-06-25 19:30 UTC
CWE-78

Weakness-Klassen (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-03 13:05 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/34xxx/CVE-2026-34982.json">CVE-2026-34982</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:59831
  2. CVE Modified2026-08-31 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:56786
    • Reference: https://access.redhat.com/errata/RHSA-2026:56853
    • Reference: https://access.redhat.com/errata/RHSA-2026:56911
  3. CVE Modified2026-08-25 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:58981

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_ai3.0

  • linux

    ubuntu / jqbionic

  • linux

    ubuntu / jqfocal

  • linux

    ubuntu / popplerjammy

  • linux

    ubuntu / popplernoble

  • linux

    ubuntu / popplerquesting

  • linux

    ubuntu / popplerresolute

  • other

    siemens / sinec_os

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • encode

    starlette0.8.3 – 1.0.1

  • encode

    starlette1.1.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • jqlang

    jq2026-04-12

  • libcap_project

    libcap

  • libsndfile_project

    libsndfile

  • libtiff

    libtiff

  • openbsd

    openssh10.3

  • openexr

    openexr3.1.0 – 3.2.7

  • openexr

    openexr3.3.0 – 3.3.9

  • openexr

    openexr3.4.0 – 3.4.9

  • pyasn1

    pyasn10.6.2

  • pyjwt_project

    pyjwt2.13.0

  • pypi

    vllm0.0.1

  • pypi

    vllm0.1.0

  • pypi

    vllm0.10.0

  • pypi

    vllm0.10.1

  • pypi

    vllm0.10.1.1

  • pypi

    vllm0.10.2

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-34982
Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm) — CVE-2026-34982 | NEOSEC Intel