<div class="container">
<h1>Security update for vim</h1>
<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2026:22754-1</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2026-07-18T11:47:56Z</td>
</tr>
<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1271193">bsc#1271193</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1271194">bsc#1271194</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1271195">bsc#1271195</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>
Cross-References:
</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-59856.html">CVE-2026-59856</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-59857.html">CVE-2026-59857</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-59858.html">CVE-2026-59858</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59856</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.4</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59856</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59856</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.4</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59856</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59857</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.6</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59857</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">4.7</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59857</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">5.6</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59857</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">5.5</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59858</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.4</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59858</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59858</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.4</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-59858</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
</ul>
</td>
</tr>
<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">
<li class="list-group-item">SUSE Linux Micro 6.2</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>An update that solves three vulnerabilities can now be installed.</p>
<h2>Description:</h2>
<p>This update for vim fixes the following issues:</p>
<p>Update to version 9.2.0780.</p>
<p>Security issues fixed:</p>
<ul>
<li>CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194).</li>
<li>CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195).</li>
<li>CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193).</li>
</ul>
<p>Other updates and bugfixes:</p>
<ul>
<li>Version 9.2.0780 changelog:</li>
<li>filetype detect missing from completion (9.2.0726).</li>
<li>popup images not rendered correctly when unfocused (9.2.0727).</li>
<li>filetype: supertux info pattern is relative to current dir
(9.2.0728).</li>
<li>% skips parens on continued quoted lines (9.2.0729).</li>
<li>GTK4 GUI tabline is not updated (9.2.0730).</li>
<li>GTK4 GUI scrollbar size not updated when restoring a session
(9.2.0731).</li>
<li>session: terminal restored using absolute columns/rows (9.2.0732).</li>
<li>GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733).</li>
<li>function pointer passed to STRNCMP() instead of a length
(9.2.0734).</li>
<li>tests: comment test can be improved (9.2.0737).</li>
<li>completion: 'autocompletedelay' blocks the main loop and drops
autocommands (9.2.0739).</li>
<li>GTK4: scrollbar wrongly displayed (9.2.0740).</li>
<li>complete_check() does not return TRUE for mapped input (9.2.0741).</li>
<li>filetype: SSH keys and related filetypes not recognized (9.2.0742).</li>
<li>string macros silently accept a size of the wrong type (9.2.0743).</li>
<li>popup_atcursor() closes immediately on white space (9.2.0744).</li>
<li>cscope: connection leak when growing the array fails (9.2.0747).</li>
<li>'autocompletedelay' interferes with CTRL-G U (9.2.0748).</li>
<li>'autocompletedelay' interferes with i_CTRL-K (9.2.0749).</li>
<li>completion: 'autocompletedelay' deferral leaks state (9.2.0750).</li>
<li>GTK3 GUI is slow under Wayland (9.2.0751).</li>
<li>GTK4: drag-and-drop does not support HTML (9.2.0752).</li>
<li>GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753).</li>
<li>repeated completion length lookup in search_for_exact_line
(9.2.0754).</li>
<li>'autocomplete' behaves inconsistently when recording (9.2.0755).</li>
<li>session with multiple tabpages sets 'winminheight' to 0 (9.2.0756).</li>
<li>tests: test_popupwin fails with zsh because of the prompt
(9.2.0757).</li>
<li>pum: no opacity when background not set for Popup menu group
(9.2.0758).</li>
<li>some code for 'autocompletedelay' is no longer needed (9.2.0759).</li>
<li>compiler warning for using potentially uninitialized var
(9.2.0760).</li>
<li>runtime(netrw): Unix: unable to open '\' file (9.2.0761).</li>
<li>duplicated sub-option name check in :set completion (9.2.0762).</li>
<li>tests: style issue in test_plugin_netrw (9.2.0763).</li>
<li>compiler warning about unused function (9.2.0764).</li>
<li>popup: opacity popup over a terminal is not cleared when moved
(9.2.0765).</li>
<li>quick_tab entries for empty letters point to the wrong index
(9.2.0766).</li>
<li>legacy/vim9cmd modifiers do not set script version for options
values (9.2.0767).</li>
<li>legacy/vim9cmd modifiers are not exclusive (9.2.0768).</li>
<li>conversion to utf-16be using iconv is inconsistent (9.2.0769).</li>
<li>dict_add_dict() has inconsistent ownership on failure (9.2.0770).</li>
<li>dict_add_list() has inconsistent ownership on failure (9.2.0771).</li>
<li>Vim9: null dereference inside alloc_type() (9.2.0772).</li>
<li>memory leak in evalfunc.c on alloc failure (9.2.0773).</li>
<li>memory leak in f_getscriptinfo() on alloc failure (9.2.0774).</li>
<li>memory leak in highlight_get_info() on alloc failure (9.2.0775).</li>
<li>memory leak in sign_getlist() on alloc failure (9.2.0776).</li>
<li>memory leak in add_defer() on alloc failure (9.2.0777).</li>
<li>memory leak in compile_dict() on alloc failure (9.2.0778).</li>
<li>memory leak in type_name_func() on alloc failure (9.2.0779).</li>
<li>memory leak in evalvars.c on alloc failure (9.2.0780).</li>
</ul>
<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">
<li class="list-group-item">
SUSE Linux Micro 6.2
<br/>
<code>zypper in -t patch SUSE-SL-Micro-6.2-1283=1</code>
</li>
</ul>
<h2>Package List:</h2>
<ul>
<li>
SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64)
<ul>
<li>vim-debuginfo-9.2.0780-160000.1.1</li>
<li>vim-small-debuginfo-9.2.0780-160000.1.1</li>
<li>vim-debugsource-9.2.0780-160000.1.1</li>
<li>vim-small-9.2.0780-160000.1.1</li>
</ul>
</li>
<li>
SUSE Linux Micro 6.2 (noarch)
<ul>
<li>vim-data-common-9.2.0780-160000.1.1</li>
</ul>
</li>
</ul>
<h2>References:</h2>
<ul>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-59856.html">https://www.suse.com/security/cve/CVE-2026-59856.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-59857.html">https://www.suse.com/security/cve/CVE-2026-59857.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-59858.html">https://www.suse.com/security/cve/CVE-2026-59858.html</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1271193">https://bugzilla.suse.com/show_bug.cgi?id=1271193</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1271194">https://bugzilla.suse.com/show_bug.cgi?id=1271194</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1271195">https://bugzilla.suse.com/show_bug.cgi?id=1271195</a>
</li>
</ul>
</div>