CVE-2026-52858

Red Hat Security Advisory: Red Hat Update Infrastructure 5.3 Technology Preview security update

Beschreibung

Vim ist ein quelloffenes Texteditor für die Kommandozeile. Vor Version 9.2.0561 führt das Python-Omni-Vervollständigungsskript python3complete.vim in Vim mit dem aktivierten +python3-Interpreter (und das veraltete pythoncomplete.vim für Builds mit dem +python-Interpreter) die import- und from-Anweisungen aus, die im aktuellen Buffer gefunden werden, durch Python's Importmechanismus. Da der Arbeitsverzeichnis des Buffers in sys.path enthalten ist, führt das Öffnen einer feindlichen .py-Datei mit einem benachbarten Python-Paket und das Aufrufen der Omni-Vervollständigung den Top-Level-Code dieses Pakets als Bearbeitungsbenutzer aus. Dieses Problem wurde in Version 9.2.0561 behoben.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.3
Quelle: nvd-v4
10.1 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 11:15 UTC
CWE-94, CWE-95, CWE-829

Weakness-Klassen (CWE)

  • CWE-94Base

    Improper Control of Generation of Code ('Code Injection')

    The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

    cwe.mitre.org →
  • CWE-95Variant

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

    The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

    cwe.mitre.org →
  • CWE-829Base

    Inclusion of Functionality from Untrusted Control Sphere

    The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-06-15 13:32 UTC· nvd@nist.gov
    • CVSS V3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    • CPE Configuration: OR *cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* versions up to (excluding) 9.2.0561
    • Reference Type: GitHub, Inc.: https://github.com/vim/vim/commit/4b850457e12e1a678dd209f2868154f7553cbf8d Types: Patch
    • Reference Type: GitHub, Inc.: https://github.com/vim/vim/releases/tag/v9.2.0561 Types: Product

Betroffene Betriebssysteme

  • linux

    ubuntu / coreutilsjammy

  • linux

    ubuntu / coreutilsnoble

  • linux

    ubuntu / coreutilsresolute

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux10.2

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux9.8

  • linux

    redhat / enterprise_linux_for_els10.2

  • linux

    redhat / enterprise_linux_for_els8.10

  • linux

    redhat / enterprise_linux_for_els9.8

  • linux

    redhat / enterprise_linux_for_eus10.2

  • linux

    redhat / enterprise_linux_for_eus9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems8.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems9.0_s390x

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els8.10

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_els9.8

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus10.2

  • linux

    redhat / enterprise_linux_for_ibm_z_systems_eus9.8

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    jre1.9.0

  • bitnami

    nginx-gateway0.1.17

  • bitnami

    nginx-gateway-fabric1.3.0

  • bitnami

    postgresql15.0.0

  • bitnami

    postgresql16.0.0

  • bitnami

    postgresql17.0.0

  • bitnami

    postgresql18.0.0

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • f5

    dos4.3.0 – 4.7.0

  • f5

    dos

  • f5

    nginx_gateway_fabric1.3.0 – 1.6.2

  • f5

    nginx_gateway_fabric2.0.0 – 2.5.1

  • f5

    nginx_ingress_controller3.5.0 – 3.7.2

  • f5

    nginx_ingress_controller4.0.0 – 4.0.1

  • f5

    nginx_ingress_controller5.0.0 – 5.4.1

Quellen & Referenzen

Verknüpfte CVEs

93 weitere CVEs anzeigen
IDCVE-2026-52858