{"id":"SUSE-SU-2026:22754-1","summary":"Security update for vim","details":"This update for vim fixes the following issues:\n\nUpdate to version 9.2.0780.\n\nSecurity issues fixed:\n\n- CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194).\n- CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195).\n- CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193).\n\nOther updates and bugfixes:\n\n- Version 9.2.0780 changelog:\n  * filetype detect missing from completion (9.2.0726).\n  * popup images not rendered correctly when unfocused (9.2.0727).\n  * filetype: supertux info pattern is relative to current dir\n    (9.2.0728).\n  * % skips parens on continued quoted lines (9.2.0729).\n  * GTK4 GUI tabline is not updated (9.2.0730).\n  * GTK4 GUI scrollbar size not updated when restoring a session\n    (9.2.0731).\n  * session: terminal restored using absolute columns/rows (9.2.0732).\n  * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733).\n  * function pointer passed to STRNCMP() instead of a length\n    (9.2.0734).\n  * tests: comment test can be improved (9.2.0737).\n  * completion: 'autocompletedelay' blocks the main loop and drops\n    autocommands (9.2.0739).\n  * GTK4: scrollbar wrongly displayed (9.2.0740).\n  * complete_check() does not return TRUE for mapped input (9.2.0741).\n  * filetype: SSH keys and related filetypes not recognized (9.2.0742).\n  * string macros silently accept a size of the wrong type (9.2.0743).\n  * popup_atcursor() closes immediately on white space (9.2.0744).\n  * cscope: connection leak when growing the array fails (9.2.0747).\n  * 'autocompletedelay' interferes with CTRL-G U (9.2.0748).\n  * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749).\n  * completion: 'autocompletedelay' deferral leaks state (9.2.0750).\n  * GTK3 GUI is slow under Wayland (9.2.0751).\n  * GTK4: drag-and-drop does not support HTML (9.2.0752).\n  * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753).\n  * repeated completion length lookup in search_for_exact_line\n    (9.2.0754).\n  * 'autocomplete' behaves inconsistently when recording (9.2.0755).\n  * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756).\n  * tests: test_popupwin fails with zsh because of the prompt\n    (9.2.0757).\n  * pum: no opacity when background not set for Popup menu group\n    (9.2.0758).\n  * some code for 'autocompletedelay' is no longer needed (9.2.0759).\n  * compiler warning for using potentially uninitialized var\n    (9.2.0760).\n  * runtime(netrw): Unix: unable to open '\\' file (9.2.0761).\n  * duplicated sub-option name check in :set completion (9.2.0762).\n  * tests: style issue in test_plugin_netrw (9.2.0763).\n  * compiler warning about unused function (9.2.0764).\n  * popup: opacity popup over a terminal is not cleared when moved\n    (9.2.0765).\n  * quick_tab entries for empty letters point to the wrong index\n    (9.2.0766).\n  * legacy/vim9cmd modifiers do not set script version for options\n    values (9.2.0767).\n  * legacy/vim9cmd modifiers are not exclusive (9.2.0768).\n  * conversion to utf-16be using iconv is inconsistent (9.2.0769).\n  * dict_add_dict() has inconsistent ownership on failure (9.2.0770).\n  * dict_add_list() has inconsistent ownership on failure (9.2.0771).\n  * Vim9: null dereference inside alloc_type() (9.2.0772).\n  * memory leak in evalfunc.c on alloc failure (9.2.0773).\n  * memory leak in f_getscriptinfo() on alloc failure (9.2.0774).\n  * memory leak in highlight_get_info() on alloc failure (9.2.0775).\n  * memory leak in sign_getlist() on alloc failure (9.2.0776).\n  * memory leak in add_defer() on alloc failure (9.2.0777).\n  * memory leak in compile_dict() on alloc failure (9.2.0778).\n  * memory leak in type_name_func() on alloc failure (9.2.0779).\n  * memory leak in evalvars.c on alloc failure (9.2.0780).\n","modified":"2026-07-23T18:24:08.988311724Z","published":"2026-07-18T11:47:56Z","related":["CVE-2026-59856","CVE-2026-59857","CVE-2026-59858"],"upstream":["CVE-2026-59856","CVE-2026-59857","CVE-2026-59858"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622754-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271193"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271194"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271195"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59858"}],"affected":[{"package":{"name":"vim","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"vim-data-common":"9.2.0780-160000.1.1","vim-small":"9.2.0780-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22754-1.json"}}],"schema_version":"1.7.5"}