{"id":"SUSE-SU-2026:3458-1","summary":"Security update for vim","details":"This update for vim fixes the following issues:\n\nThis update for vim fixes the following issues:\n\nSecurity issues fixed:\n\n- CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194).\n- CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195).\n- CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193).\n\nNon security issue fixed:\n\n- Guard suse.vimrc against re-entry to prevent an infinite sourcing\n loop (bsc#1271684).\n- allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162).\n\nChanges for vim:\n  \n- Updated to version 9.2.0780:\n\n * filetype detect missing from completion (9.2.0726).\n * popup images not rendered correctly when unfocused (9.2.0727).\n * filetype: supertux info pattern is relative to current dir\n (9.2.0728).\n * % skips parens on continued quoted lines (9.2.0729).\n * GTK4 GUI tabline is not updated (9.2.0730).\n * GTK4 GUI scrollbar size not updated when restoring a session\n (9.2.0731).\n * session: terminal restored using absolute columns/rows (9.2.0732).\n * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733).\n * function pointer passed to STRNCMP() instead of a length\n (9.2.0734).\n * tests: comment test can be improved (9.2.0737).\n * completion: 'autocompletedelay' blocks the main loop and drops\n autocommands (9.2.0739).\n * GTK4: scrollbar wrongly displayed (9.2.0740).\n * complete_check() does not return TRUE for mapped input (9.2.0741).\n * filetype: SSH keys and related filetypes not recognized (9.2.0742).\n * string macros silently accept a size of the wrong type (9.2.0743).\n * popup_atcursor() closes immediately on white space (9.2.0744).\n * cscope: connection leak when growing the array fails (9.2.0747).\n * 'autocompletedelay' interferes with CTRL-G U (9.2.0748).\n * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749).\n * completion: 'autocompletedelay' deferral leaks state (9.2.0750).\n * GTK3 GUI is slow under Wayland (9.2.0751).\n * GTK4: drag-and-drop does not support HTML (9.2.0752).\n * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753).\n * repeated completion length lookup in search_for_exact_line\n (9.2.0754).\n * 'autocomplete' behaves inconsistently when recording (9.2.0755).\n * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756).\n * pum: no opacity when background not set for Popup menu group\n (9.2.0758).\n * some code for 'autocompletedelay' is no longer needed (9.2.0759).\n * compiler warning for using potentially uninitialized var\n (9.2.0760).\n * runtime(netrw): Unix: unable to open '\\' file (9.2.0761).\n * duplicated sub-option name check in :set completion (9.2.0762).\n * compiler warning about unused function (9.2.0764).\n * popup: opacity popup over a terminal is not cleared when moved\n (9.2.0765).\n * quick_tab entries for empty letters point to the wrong index\n (9.2.0766).\n * legacy/vim9cmd modifiers do not set script version for options\n values (9.2.0767).\n * legacy/vim9cmd modifiers are not exclusive (9.2.0768).\n * conversion to utf-16be using iconv is inconsistent (9.2.0769).\n * dict_add_dict() has inconsistent ownership on failure (9.2.0770).\n * dict_add_list() has inconsistent ownership on failure (9.2.0771).\n * Vim9: null dereference inside alloc_type() (9.2.0772).\n * memory leak in evalfunc.c on alloc failure (9.2.0773).\n * memory leak in f_getscriptinfo() on alloc failure (9.2.0774).\n * memory leak in highlight_get_info() on alloc failure (9.2.0775).\n * memory leak in sign_getlist() on alloc failure (9.2.0776).\n * memory leak in add_defer() on alloc failure (9.2.0777).\n * memory leak in compile_dict() on alloc failure (9.2.0778).\n * memory leak in type_name_func() on alloc failure (9.2.0779).\n * memory leak in evalvars.c on alloc failure (9.2.0780).\n  \n- Updated to version 9.2.0725:\n \n * GTK: preedit font size is wrong for fractional point sizes (9.2.0532).\n * '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533).\n * GTK UI does not support fullscreen mode (9.2.0534).\n * GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537).\n * Cannot keep leading whitespace in %{} statusline expr (9.2.0538).\n * filetype: too many Bitbake include files are recognized (9.2.0539).\n * Vim9: endclass/endenum/endinterface can give errors (9.2.0541).\n * Vim9: wrong error when redeclaring a typed variable (9.2.0543).\n * GTK4: window blank after a resize or drag (9.2.0544).\n * popup: blending uses hardcoded fallback colors (9.2.0545).\n * configure: GTK4 build requires GTK \u003e= 4.10 (9.2.0546).\n * '%v' in 'errorformat' is affected by 'tabstop' (9.2.0547).\n * GTK4: terminal and pty job output is not processed (9.2.0548).\n * Cursor wrong after autoindent strip is skipped (9.2.0549).\n * GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550).\n * filetype: Tolk files are not recognized (9.2.0551).\n * GTK4: F10 does nothing when the menubar is hidden (9.2.0552).\n * runtime(netrw): netrw rejects hostnames containing _ (9.2.0553).\n * GTK4: memory leak in free_menu() (9.2.0554).\n * too many strlen() in ex_substitute() (9.2.0555).\n * GTK4: scrollbars not shown and do not respond to clicks (9.2.0556).\n * filetype: Kawasaki Robots files are not recognized (9.2.0557).\n * filetype: Popcap Reanimation files are not recognized (9.2.0558).\n * filetype: Kaitai struct files are not recogonized (9.2.0559).\n * filetype: busybox shebang lines are not recognized (9.2.0560).\n * [security]: possible code execution with python3complete (9.2.0561).\n * filetype: SGF files are not recognized (9.2.0562).\n * GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563).\n * GTK4: tabline does not respond to mouse clicks (9.2.0564).\n * [security]: out-of-bounds read in update_snapshot() (9.2.0565).\n * \u003cC-w\u003ef duplicates window if do_ecmd() is aborted (9.2.0566).\n * dict function name allocation failure not handled (9.2.0567).\n * pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568).\n * out-of-bounds access in libvterm CSI 8 t resize (9.2.0569).\n * GTK4: mouse wheel scrolling does not work correctly (9.2.0570).\n * Vim9: memory leak in compile_nested_function() on failure (9.2.0571).\n * lines disappear with wrapping virtual text after a double-width char (9.2.0572).\n * Vim9: missing EX_WHOLE on some block keywords (9.2.0573).\n * popup_create() not blocked in secure/sandbox (9.2.0576).\n * GTK4: window resizing issues (9.2.0577).\n * GTK4: :unmenu does not remove entries from the menubar (9.2.0578).\n * :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579).\n * xxd: binary output is not colored with -R (9.2.0580).\n * After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581).\n * GTK4: compile error when XFONTSET is defined (9.2.0582).\n * completion: indent not ignored for fuzzy line completion (9.2.0583).\n * GTK4: missing UI features (9.2.0584).\n * line number wrong after undoing a deletion in quickfix buffer (9.2.0585).\n * Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586).\n * GTK4: left scrollbar overlaps drawarea (9.2.0587).\n * GTK4: drawing area loses focus after closing a menubar popover (9.2.0588).\n * filetype: xinitrc files are not recognized (9.2.0589).\n * GTK4: drawing area loses focus shape on popup menu open (9.2.0590).\n * 'scrolljump' ignored when scrolling up (9.2.0591).\n * Error when restoring session with terminal window (9.2.0592).\n * :wqall ignores term_setkill() on running terminal buffers (9.2.0593).\n * Use-after-free with ':wqall' and a running terminal job (9.2.0594).\n * MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595).\n * cmdline completion popup cannot be scrolled with the mouse (9.2.0596).\n * [security]: possible code execution with python complete (9.2.0597).\n * popup: title set with popup_setoptions() is not shown (9.2.0599).\n * clientserver method needs to be given as argument (9.2.0600).\n * matchfuzzypos() returns garbage positions for long candidates (9.2.0601).\n * popup: No opacity when background not set for Popup group (9.2.0602).\n * possible heap-buffer-overflow when resizing the GUI (9.2.0603).\n * GTK4: does not support all clipboard formats (9.2.0606).\n * GTK4: inputdialog() does not work as expected (9.2.0607).\n * popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608).\n * completion info popup cannot be scrolled with the keyboard (9.2.0609).\n * cindent: closing brace in a comment affects the next line's indent (9.2.0610).\n * MS-Windows: evim.exe not working with VIMDLL (9.2.0611).\n * Cannot render images in popup windows (9.2.0612).\n * opacity popup leaves stale cells (9.2.0614).\n * sixel encoder drops pixels on the right edge of shapes (9.2.0615).\n * GTK4: use-after-free on clipboard read timeout (9.2.0616).\n * GvimExt: does not support different runtime dirs (9.2.0617).\n * use-after-free in popup_getoptions() on dict_add() failure (9.2.0618).\n * integer overflow in popup image size validation (9.2.0619).\n * runtime(netrw): fix 2match pattern rebuild (9.2.0620).\n * 'autoindent' not stripped with virtualedit=onemore (9.2.0621).\n * str2blob() does not work with wide UTF-16 encoding (9.2.0622).\n * possible integer overflow in spellfile tree bounds check (9.2.0623).\n * C-N/C-P cannot be mapped in complete() completion (9.2.0624).\n * GTK4: Link error when Wayland is disabled (9.2.0625).\n * Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626).\n * :vim9cmd source handles all scripts as Vim9 script (9.2.0627).\n * popup image: wrong overlap layering, kitty laggy (9.2.0628).\n * 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629).\n * popup images: kitty images output in GUI mode (9.2.0630).\n * DECRQM and SGR Mouse not supported in foot terminal (9.2.0631).\n * GTK4: no support for hardware-accelerated rendering (9.2.0632).\n * MS-Windows: No support for kitty graphics support in terminal (9.2.0633).\n * GTK4: no minimum resize limit (9.2.0634).\n * checking the syntax contains/cluster list is slow (9.2.0635).\n * popup image: stale pixels under RGBA animation frames (9.2.0636).\n * sixel: anti-aliased RGBA images render with visible outline (9.2.0637).\n * cannot return matches containing spaces from a custom completion (9.2.0638).\n * gq with 'formatprg' fails on an empty buffer (9.2.0639).\n * the '%' command jumps to parens and braces inside comments (9.2.0640).\n * GTK4: crash in gui_mch_menu_hidden() (9.2.0641).\n * statusline: buffer overflow with item groups (9.2.0642).\n * Missing Image ifdefs (9.2.0643).\n * popup image: duplicate sync-output code (9.2.0644).\n * Composing chars no longer accepted in end-id abbr (9.2.0645).\n * GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646).\n * matchfuzzypos() false exact match for long equal-length candidates (9.2.0647).\n * MS-Windows: Compile warnings (9.2.0648).\n * filetype: tf files sometimes incorrectly recognized (9.2.0649).\n * Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650).\n * completion: 'smartcase' doesn't work with 'longest' (9.2.0651).\n * popup: stale kitty image after clipwindow scrolls out of view (9.2.0652).\n * [security]: out-of-bounds write in tree_count_words() (9.2.0653).\n * GTK4: using uninitialised colors in gui_mch_init() (9.2.0654).\n * GTK4: missing NULL checks in vim_form_measure() (9.2.0655).\n * completion: using wrong tolower() in smartcase filtering (9.2.0656).\n * GTK4: missing menu when right-clicking in tabline (9.2.0657).\n * xxd: signed integer overflow in huntype() (9.2.0658).\n * GTK4: no balloon support in GUI (9.2.0659).\n * Dragging the scrollbar does not trigger WinScrolled (9.2.0660).\n * unintended wipe of Vim's temp dir, causes errors (9.2.0661).\n * [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662).\n * [security]: runtime(netrw): code injection in local file deletion (9.2.0663).\n * GTK4: GTK critical error on exit printed (9.2.0665).\n * Terminal-Normal mode does not color empty lines with a background color (9.2.0666).\n * patch 9.2.0590 was wrong (9.2.0667).\n * GTK4: minimum horizontal size is too small (9.2.0668).\n * GTK4: toolbar can be improved (9.2.0669).\n * [security]: Out-of-bounds read with text properties (9.2.0670).\n * [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671).\n * corrupted text property causes internal error (9.2.0672).\n * configure: clears dynamic ruby linker flags (9.2.0674).\n * MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676).\n * Cannot clear the alternate file register # (9.2.0677).\n * [security]: potential powershell code execution in zip.vim (9.2.0678).\n * [security]: Out-of-bounds read with text property virtual text (9.2.0679).\n * keytrans() doesn't replace '|' and '\\' (9.2.0680).\n * configure: -lruby added even for a dynamic ruby build (9.2.0681).\n * Wrong dot-repeat when calling complete() while filtering completion (9.2.0682).\n * filetype completion mishandles finished sub options (9.2.0683).\n * :reg # does not display the value of the '#' register (9.2.0684).\n * clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685).\n * style: strcmp usage is inconsistent (9.2.0686).\n * popup_image_composites_frames() has improper if block scope (9.2.0687).\n * Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688).\n * the '%' command is slow on a long line with many slashes (9.2.0689).\n * Solaris: swap file names are too long (9.2.0690).\n * Solaris: Test_terminal_composing_unicode() fails (9.2.0691).\n * GTK2: build failure, popup images not drawn correctly (9.2.0692).\n * Solaris: some tests faiures due to Solaris peculiarities (9.2.0694).\n * Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695).\n * GTK4: A few issues with toolbar support (9.2.0696).\n * possible overflow when parsing CSI keys (9.2.0697).\n * [security]: Out-of-bounds write with soundfold() (9.2.0698).\n * [security]: possible code execution with python complete (9.2.0699).\n * configure: -lrt requirement for timer_create not detected (9.2.0700).\n * :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702).\n * session file does not store relative Vim9 autoload imports (9.2.0703).\n * GTK4: not handling mouse events (9.2.0704).\n * :delete # silently fails to update '# and clobbers '0 (9.2.0705).\n * completion: popup misplaced when text before it is concealed (9.2.0707).\n * Leaks in do_autocmd in error case (9.2.0708).\n * GTK4: a few minor issues (9.2.0709).\n * GTK4 GUI resize handling can be improved (9.2.0710).\n * leak in ins_compl_infercase_gettext() in error case (9.2.0711).\n * GTK4: dialogs not handling mnemonics correctly (9.2.0712).\n * completion: ruler not updated correctly when the popup menu is visible (9.2.0713).\n * Coverity warns for NULL deref (9.2.0714).\n * Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715).\n * filetype: not all supertux files are recognized (9.2.0716).\n * :syn sync without an argument also lists syntax cluster (9.2.0718).\n * GTK4: default menu is lacking (9.2.0719).\n * GTK4: no support for browsefilter (9.2.0720).\n * serverlist() returns strings separated by \\n (9.2.0721).\n * GTK4: find/replace dialog can be improved (9.2.0722).\n * term_start() does not support 'noclose' (9.2.0723).\n * use-after-free when freeing exit_cb job on exit (9.2.0724).\n","modified":"2026-08-04T11:45:05.101890571Z","published":"2026-08-03T12:01:08Z","related":["CVE-2026-59856","CVE-2026-59857","CVE-2026-59858"],"upstream":["CVE-2026-59856","CVE-2026-59857","CVE-2026-59858"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263458-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268162"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271193"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271194"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271195"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59858"}],"affected":[{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise Micro 5.5","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Micro%205.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP7","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim-data":"9.2.0780-150500.20.61.2","vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2","vim":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise Module for Desktop Applications 15 SP7","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"gvim":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim":"9.2.0780-150500.20.61.2","vim-data":"9.2.0780-150500.20.61.2","vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2","gvim":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2","gvim":"9.2.0780-150500.20.61.2","vim":"9.2.0780-150500.20.61.2","vim-data":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2","gvim":"9.2.0780-150500.20.61.2","vim":"9.2.0780-150500.20.61.2","vim-data":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim":"9.2.0780-150500.20.61.2","vim-data":"9.2.0780-150500.20.61.2","vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2","gvim":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim-data":"9.2.0780-150500.20.61.2","vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2","gvim":"9.2.0780-150500.20.61.2","vim":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}},{"package":{"name":"vim","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.2.0780-150500.20.61.2"}]}],"ecosystem_specific":{"binaries":[{"vim-data":"9.2.0780-150500.20.61.2","vim-data-common":"9.2.0780-150500.20.61.2","vim-small":"9.2.0780-150500.20.61.2","gvim":"9.2.0780-150500.20.61.2","vim":"9.2.0780-150500.20.61.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3458-1.json"}}],"schema_version":"1.8.0"}