Home / mailings [USN-8679-2] Vim vulnerability
Posted on 09 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8679-2
September 08, 2026
vim vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
Summary:
Vim could be made to crash or run programs as your login if it opened
a specially crafted file.
Software Description:
- vim: Vi IMproved - enhanced vi editor
Details:
USN-8679-1 fixed a vulnerability in Vim. This update provides the
corresponding update for Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that Vim incorrectly handled certain tags files. An
attacker could possibly use this issue to execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
vim 2:9.1.2141-1ubuntu4.9
vim-common 2:9.1.2141-1ubuntu4.9
vim-doc 2:9.1.2141-1ubuntu4.9
vim-gtk3 2:9.1.2141-1ubuntu4.9
vim-gui-common 2:9.1.2141-1ubuntu4.9
vim-motif 2:9.1.2141-1ubuntu4.9
vim-nox 2:9.1.2141-1ubuntu4.9
vim-runtime 2:9.1.2141-1ubuntu4.9
vim-tiny 2:9.1.2141-1ubuntu4.9
xxd 2:9.1.2141-1ubuntu4.9
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8679-2
https://ubuntu.com/security/notices/USN-8679-1
CVE-2026-73073
Package Information:
https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubuntu4.9
--===============0740122335762679035==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
