<div class="container">
<h1>Security update for vim</h1>
<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2026:3679-1</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2026-08-21T14:20:53Z</td>
</tr>
<tr>
<th>Rating:</th>
<td>important</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275011">bsc#1275011</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275012">bsc#1275012</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275013">bsc#1275013</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275014">bsc#1275014</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275015">bsc#1275015</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275016">bsc#1275016</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275017">bsc#1275017</a>
</li>
<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275018">bsc#1275018</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>
Cross-References:
</th>
<td>
<ul>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73070.html">CVE-2026-73070</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73071.html">CVE-2026-73071</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73072.html">CVE-2026-73072</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73074.html">CVE-2026-73074</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73075.html">CVE-2026-73075</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73076.html">CVE-2026-73076</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73077.html">CVE-2026-73077</a>
</li>
<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-73078.html">CVE-2026-73078</a>
</li>
</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73070</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">5.8</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73070</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">6.1</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73070</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">6.8</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73071</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">2.0</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73071</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">3.3</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73071</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">3.3</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73072</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.3</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73072</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73072</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.5</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73074</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.3</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73074</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73074</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">7.1</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73075</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">2.0</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73075</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">4.4</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73075</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">4.6</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73076</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">8.4</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73076</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73076</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.4</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73077</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.3</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73077</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73077</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.4</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73078</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.3</span>
<span class="cvss-vector">CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73078</span>
<span class="cvss-source">
(
SUSE
):
</span>
<span class="cvss-score">7.8</span>
<span class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</span>
</li>
<li class="list-group-item">
<span class="cvss-reference">CVE-2026-73078</span>
<span class="cvss-source">
(
NVD
):
</span>
<span class="cvss-score">8.6</span>
<span class="cvss-vector">CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</span>
</li>
</ul>
</td>
</tr>
<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise High Performance Computing LTSS 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Micro 5.3</li>
<li class="list-group-item">SUSE Linux Enterprise Micro 5.4</li>
<li class="list-group-item">SUSE Linux Enterprise Micro for Rancher 5.3</li>
<li class="list-group-item">SUSE Linux Enterprise Micro for Rancher 5.4</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP4</li>
<li class="list-group-item">SUSE Linux Enterprise Server 15 SP4 LTSS</li>
<li class="list-group-item">SUSE Linux Enterprise Server for SAP Applications 15 SP4</li>
</ul>
</td>
</tr>
</tbody>
</table>
<p>An update that solves eight vulnerabilities can now be installed.</p>
<h2>Description:</h2>
<p>This update for vim fixes the following issues:</p>
<ul>
<li>CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018).</li>
<li>CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017).</li>
<li>CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution
(bsc#1275016).</li>
<li>CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution
(bsc#1275015).</li>
<li>CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014).</li>
<li>CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013).</li>
<li>CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012).</li>
<li>CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011).</li>
</ul>
<p>Changes for vim:</p>
<ul>
<li>Updated to version 9.2.0957.</li>
<li>tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781).</li>
<li>tests: missing cleanup in test_mksession.vim (9.2.0782).</li>
<li>tests: personal spell files leak into later tests (9.2.0783).</li>
<li>crash when borrowing statusline highlight in silent Ex mode (9.2.0784).</li>
<li>WinResized not triggered when the whole Vim is resized (9.2.0785).</li>
<li>filetype: containerfile is not recognized (9.2.0786).</li>
<li>regexp: code 0x1ecb duplicated for equivalence class (9.2.0787).</li>
<li>filetype: hip files are not recognized (9.2.0788).</li>
<li>'statuslineopt' status line too high after a window is minimized (9.2.0789).</li>
<li>'completeslash' breaks :find completion with 'findfunc' (9.2.0790).</li>
<li>wincol() counts from right side for 'rightleft' (9.2.0791).</li>
<li>runtime(netrw): explore without optional dir broken (9.2.0792).</li>
<li>if session restored a tiny window, restore fails (9.2.0793).</li>
<li>extend() and extendnew() don't handle NULL expr2 properly (9.2.0794).</li>
<li>popup menu shadow is not cleared when the menu shrinks (9.2.0795).</li>
<li>Visual block reselection wrong with 'virtualedit' (9.2.0796).</li>
<li>memory leak in get_qfline_items() on alloc failure (9.2.0797).</li>
<li>memory leak in compile_expr6() on alloc failure (9.2.0798).</li>
<li>memory leak in compile_def_function_body() on alloc failure (9.2.0799).</li>
<li>memory leak in call_func() on alloc failure (9.2.0800).</li>
<li>memory leak in f_getreginfo() on alloc failure (9.2.0801).</li>
<li>memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802).</li>
<li>memory leak on alloc failure with taglist/gettagstack() (9.2.0803).</li>
<li>wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804).</li>
<li>screenpos() "curscol" is wrong with 'rightleft' (9.2.0805).</li>
<li>'showcmd' may show internal command keys (9.2.0806).</li>
<li>MS-Windows: ellipsis character is garbled (9.2.0807).</li>
<li>getregionpos: double-free on alloc failure (9.2.0808).</li>
<li>getframelayout() uses wrong function to free lists (9.2.0809).</li>
<li>add_llist_tags() uses wrong function to free dict (9.2.0810).</li>
<li>mksession writes terminal command unquoted (9.2.0811).</li>
<li>:argdelete with pattern leads to wrong argidx() (9.2.0812).</li>
<li>dict_add_func() may corrupt funcref count on failure (9.2.0813).</li>
<li>Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814).</li>
<li>deeply nested regexp patterns may cause stack overflow (9.2.0815).</li>
<li>GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816).</li>
<li>crash when building a stacktrace during an autocommand (9.2.0817).</li>
<li>tests: client-server test fails without X11 server (9.2.0818).</li>
<li>MS-Windows: sixel image shown as raw text in the console (9.2.0819).</li>
<li>GUI: hidden popup image is displayed and not erased (9.2.0820).</li>
<li>filetype: msmtp system-wide rc file not detected (9.2.0821).</li>
<li>GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822).</li>
<li>tests: Test_clientserver_servlist_list may fail (9.2.0823).</li>
<li>Makefile: make tags depends on configure (9.2.0824).</li>
<li>regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825).</li>
<li>highlighting for broken terminals can be improved (9.2.0826).</li>
<li>:startinsert enters Insert mode in a non-modifiable buffer (9.2.0827).</li>
<li>GTK4: hardware rendering can be improved (9.2.0828).</li>
<li>sessions do not preserve script version for expression options (9.2.0829).</li>
<li>the completion menu is not used on terminals without colors (9.2.0830).</li>
<li>diff highlighting hard to read with syntax enabled (9.2.0831).</li>
<li>socketserver: remote commands can be processed in reverse order (9.2.0832).</li>
<li>GTK4: menu mnemonics do not work properly (9.2.0833).</li>
<li>cleared last search pattern is restored from viminfo (9.2.0834).</li>
<li>features in version.c are not sorted (9.2.0835).</li>
<li>filetype: .git-blame-ignore-revs file is not recognized (9.2.0836).</li>
<li>using wrong colors in hl_blend_attr() (9.2.0837).</li>
<li>searchcount() returns wrong cached maxcount (9.2.0838).</li>
<li>[security]: arbitrary code execution via keyword lookup (9.2.0839).</li>
<li>[security]: code injection in netrw via bookmarks (9.2.0840).</li>
<li>[security]: heap overflow when adding > 65535 text properties (9.2.0841).</li>
<li>[security]: stack buffer overflow in socket server (9.2.0842).</li>
<li>[security]: popup: opacity mask indexed out of bounds (9.2.0843).</li>
<li>[security]: use-after-free on json decode error (9.2.0844).</li>
<li>[security]: arbitrary Ex command execution during C omni-completion (9.2.0845).</li>
<li>[security]: heap buffer overflow in set_sofo() (9.2.0846).</li>
<li>[security]: vimball: code execution via .VimballRecord file (9.2.0847).</li>
<li>tagfunc "cmd" with a generic Ex command corrupts the tag entry (9.2.0848).</li>
<li>filetype: osquery config files are not recognized (9.2.0849).</li>
<li>MS-Windows: commands from a client can be lost (9.2.0850).</li>
<li>focus autocommands triggered inconsistently (9.2.0851).</li>
<li>GTK: ligatures not correctly displayed (9.2.0852).</li>
<li>popup: popup images do not support scaling (9.2.0853).</li>
<li>memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854).</li>
<li>'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855).</li>
<li>GTK4: undercurl rendering is inefficient (9.2.0856).</li>
<li>popup: opacity popup over a terminal is not cleared when closed (9.2.0857).</li>
<li>MS-Windows GUI: white flash when VimEnter is slow (9.2.0858).</li>
<li>GTK2: link error (9.2.0859).</li>
<li>filetype: xilinx design constraint files are not recognized (9.2.0860).</li>
<li>GTK4: bleed region updates in jumps (9.2.0861).</li>
<li>missing test change from v9.2.0857 (9.2.0862).</li>
<li>MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863).</li>
<li>using some dead code in Wayland feature (9.2.0864).</li>
<li>GTK4: non-hardware accelerated UI is too slow (9.2.0865).</li>
<li>MS-Windows: ":language messages" only works once (9.2.0866).</li>
<li>MS-Windows: messages are not in the display language (9.2.0867).</li>
<li>GTK: window Manager hint prevents giving focus to dialog (9.2.0868).</li>
<li>buf_copy_options() can lose the P_INSECURE flag (9.2.0869).</li>
<li>filetype: marko files are not recognized (9.2.0870).</li>
<li>screen line is lost when splitting a 'winfixheight' window (9.2.0871).</li>
<li>popup with opacity does not use the font of the highlight group (9.2.0872).</li>
<li>:redrawstatus does not update the ruler of the last window (9.2.0873).</li>
<li>fold size is compared against 'foldminlines' of the wrong window (9.2.0874).</li>
<li>GTK4: GUI does not support command-line arguments (9.2.0875).</li>
<li>GTK4: compile error with disabled netbeans feat (9.2.0876).</li>
<li>Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877).</li>
<li>Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878).</li>
<li>popup: "maxwidth" is not respected when 'wrap' is off (9.2.0879).</li>
<li>scroll: window scrolls when using the autocommand window (9.2.0880).</li>
<li>'smoothscroll' position is lost when the window height changes (9.2.0881).</li>
<li>:bwipe crashes if WinLeave wipes all other buffers (9.2.0882).</li>
<li>scroll: 'smoothscroll' position is lost when using "|" (9.2.0883).</li>
<li>scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884).</li>
<li>scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885).</li>
<li>:set completion works for an invalid sub-option name (9.2.0886).</li>
<li>scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887).</li>
<li>mapping: modifier is not recognized after a partial mapping (9.2.0888).</li>
<li>VMS: spurious "INVALID DECC FEATURE VALUE" message at every startup (9.2.0889).</li>
<li>test: test for patch v9.2.0888 can be clarified (9.2.0890).</li>
<li>MS-Windows: filename-modifier ":8:t" causes underflow (9.2.0891).</li>
<li>highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892).</li>
<li>MS-Windows: "*.vim" also matches files with a longer extension (9.2.0893).</li>
<li>filetype: ed script files not recognised (9.2.0894).</li>
<li>test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895).</li>
<li>scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896).</li>
<li>GTK3 X11 redraws are not coalesced (9.2.0897).</li>
<li>printing support is lacking (9.2.0898).</li>
<li>command output temporary files may collide (9.2.0899).</li>
<li>FocusGained still triggered when closing dialog (9.2.0900).</li>
<li>textprop: wrong cursor line with truncated virtual text (9.2.0901).</li>
<li>Vim9: iterating over a tuple leaks memory (9.2.0902).</li>
<li>Vim9: cannot use an exported function of an autoload import (9.2.0903).</li>
<li>"zb" scrolls incorrectly with cursor just above fold (9.2.0904).</li>
<li>MS-Windows: ghost cursor with ligatures (9.2.0905).</li>
<li>slow transstr() with long strings (9.2.0906).</li>
<li>popup: virtual text is not redrawn when a text property changes (9.2.0907).</li>
<li>cannot use a {} block in a nested :autocmd (9.2.0908).</li>
<li>insert completion is slow to collect many matches (9.2.0909).</li>
<li>runtime(vim): update syntax, contain Ex commands (9.2.0910).</li>
<li>makefiles do not build hardcopy_postscript.c (9.2.0911).</li>
<li>hardcopy: prototypes are hand-written instead of generated (9.2.0912).</li>
<li>statusline: cell below the vertical separator keeps the old highlight (9.2.0913).</li>
<li>diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914).</li>
<li>tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915).</li>
<li>configure: honor <code>--disable-hardcopy-pango</code> with GTK UI (9.2.0916).</li>
<li>:quitall not allowed in the command-line window (9.2.0917).</li>
<li>screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918).</li>
<li>screen: the wrong array is copied into ScreenCols on a resize (9.2.0919).</li>
<li>filetype: json-ld files are not recognized (9.2.0920).</li>
<li>test: terminal tests fail on FreeBSD (9.2.0921).</li>
<li>Wayland: modeless selection not redrawn (9.2.0922).</li>
<li>tabpage: closing a tab page loses the alternate tab page (9.2.0923).</li>
<li>tests: Test_termwinscroll() fails on FreeBSD (9.2.0924).</li>
<li>crash when getcompletiontype() gets a NULL string (9.2.0925).</li>
<li>filetype: business Central files are not recognized (9.2.0926).</li>
<li>curswant not set on 8g8 (9.2.0927).</li>
<li>MinGW: tests hang when Vim is built with coverage enabled (9.2.0928).</li>
<li>incorrect completion for 'pumopt' and 'pumborder' (9.2.0929).</li>
<li>floating point exception when displaying pum (9.2.0930).</li>
<li>the GTK4 GUI is still experimental and untested by CI (9.2.0931).</li>
<li>NFA engine fallback can double free the compiled program (9.2.0932).</li>
<li>u_read_undo() leaks the file name when the undo file owner differs (9.2.0933).</li>
<li>filetype: hlsl files are not recognized (9.2.0934).</li>
<li>reading an undo file is slow with many undo headers (9.2.0935).</li>
<li>stringifying a list or dict can free the item being iterated (9.2.0936).</li>
<li>sort() with a numeric option converts each item on every comparison (9.2.0937).</li>
<li>cursorbind: cursor in the other window is not updated after undo (9.2.0938).</li>
<li>mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939).</li>
<li>GTK4: columns are lost when a scrollbar appears (9.2.0940).</li>
<li>tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941).</li>
<li>test: test_mksession_winpos() fails on GTK4 UI (9.2.0942).</li>
<li>test: test_hardcopy fails on GTK4 UI (9.2.0943).</li>
<li>test: tests fail when checking for GTK4 feature (9.2.0944).</li>
<li>sort() with a numeric option can be improved (9.2.0945).</li>
<li>GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946).</li>
<li>GTK4: screen is cleared when moving the mouse after startup (9.2.0947).</li>
<li>GTK4: mouse move starts Visual selection after a dialog (9.2.0948).</li>
<li>GDK_KEY_VoidSymbol might be undefined (9.2.0949).</li>
<li>transstr() can be improved (after 9.2.0906) (9.2.0950).</li>
<li>GTK3: cursor does no longer blink (9.2.0951).</li>
<li>locking a container while stringifying can be improved (9.2.0952).</li>
<li>insert completion code can be improved (9.2.0953).</li>
<li>u_read_undo() can be improved (after 9.2.0935) (9.2.0954).</li>
<li>tests: terminal tests are flaky (9.2.0955).</li>
<li>GTK4: crash when the window is resized while redrawing (9.2.0956).</li>
<li>filetype: ArgoCD config file is not recognized (9.2.0957).</li>
</ul>
<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".<br/>
Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">
<li class="list-group-item">
SUSE Linux Enterprise Server 15 SP4 LTSS
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3679=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Micro for Rancher 5.3
<br/>
<code>zypper in -t patch SUSE-SLE-Micro-5.3-2026-3679=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Micro 5.3
<br/>
<code>zypper in -t patch SUSE-SLE-Micro-5.3-2026-3679=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
<br/>
<code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3679=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Micro for Rancher 5.4
<br/>
<code>zypper in -t patch SUSE-SLE-Micro-5.4-2026-3679=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Micro 5.4
<br/>
<code>zypper in -t patch SUSE-SLE-Micro-5.4-2026-3679=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
<br/>
<code>zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3679=1</code>
</li>
<li class="list-group-item">
SUSE Linux Enterprise Server for SAP Applications 15 SP4
<br/>
<code>zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3679=1</code>
</li>
</ul>
<h2>Package List:</h2>
<ul>
<li>
SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
<ul>
<li>gvim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-9.2.0957-150000.5.102.1</li>
<li>gvim-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
<ul>
<li>vim-data-9.2.0957-150000.5.102.1</li>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)
<ul>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
<ul>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)
<ul>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro 5.4 (noarch)
<ul>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
<ul>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
<li>vim-data-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64)
<ul>
<li>vim-9.2.0957-150000.5.102.1</li>
<li>gvim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>gvim-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64)
<ul>
<li>gvim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-9.2.0957-150000.5.102.1</li>
<li>gvim-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
<ul>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
<li>vim-data-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
<ul>
<li>gvim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-9.2.0957-150000.5.102.1</li>
<li>gvim-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
<ul>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
<li>vim-data-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
<ul>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)
<ul>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro 5.3 (noarch)
<ul>
<li>vim-data-common-9.2.0957-150000.5.102.1</li>
</ul>
</li>
<li>
SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)
<ul>
<li>vim-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-small-debuginfo-9.2.0957-150000.5.102.1</li>
<li>vim-debugsource-9.2.0957-150000.5.102.1</li>
<li>vim-small-9.2.0957-150000.5.102.1</li>
</ul>
</li>
</ul>
<h2>References:</h2>
<ul>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73070.html">https://www.suse.com/security/cve/CVE-2026-73070.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73071.html">https://www.suse.com/security/cve/CVE-2026-73071.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73072.html">https://www.suse.com/security/cve/CVE-2026-73072.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73074.html">https://www.suse.com/security/cve/CVE-2026-73074.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73075.html">https://www.suse.com/security/cve/CVE-2026-73075.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73076.html">https://www.suse.com/security/cve/CVE-2026-73076.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73077.html">https://www.suse.com/security/cve/CVE-2026-73077.html</a>
</li>
<li>
<a href="https://www.suse.com/security/cve/CVE-2026-73078.html">https://www.suse.com/security/cve/CVE-2026-73078.html</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275011">https://bugzilla.suse.com/show_bug.cgi?id=1275011</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275012">https://bugzilla.suse.com/show_bug.cgi?id=1275012</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275013">https://bugzilla.suse.com/show_bug.cgi?id=1275013</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275014">https://bugzilla.suse.com/show_bug.cgi?id=1275014</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275015">https://bugzilla.suse.com/show_bug.cgi?id=1275015</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275016">https://bugzilla.suse.com/show_bug.cgi?id=1275016</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275017">https://bugzilla.suse.com/show_bug.cgi?id=1275017</a>
</li>
<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1275018">https://bugzilla.suse.com/show_bug.cgi?id=1275018</a>
</li>
</ul>
</div>