Amazon Linux 2023 Security Advisory: ALAS2023-2026-2108
Advisory Released Date: 2026-08-31
Advisory Updated Date: 2026-08-31
FAQs regarding Amazon Linux ALAS/CVE Severity
Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/channel.c and fixed-size struct pollfd arrays in src/os_unix.c, which allows a local process that can connect to the server socket to corrupt stack memory or terminate the Vim server. This issue is fixed in version 9.2.0842. (CVE-2026-73070)
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844. (CVE-2026-73071)
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846. (CVE-2026-73072)
Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file, allowing an unterminated collection followed by a command separator to execute arbitrary Ex and operating-system commands when a user invokes C omni-completion with CTRL-X CTRL-O on a member access whose type is resolved from that tags file. This issue is fixed in version 9.2.0845. (CVE-2026-73073)
Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue is fixed in version 9.2.0841. (CVE-2026-73074)
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843. (CVE-2026-73075)
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847. (CVE-2026-73076)
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839. (CVE-2026-73077)
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840. (CVE-2026-73078)
Affected Packages:
vim
Issue Correction:
Run dnf update vim --releasever 2023.12.20260831 or dnf update --advisory ALAS2023-2026-2108 --releasever 2023.12.20260831 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
vim-enhanced-debuginfo-9.2.920-1.amzn2023.0.1.aarch64
xxd-9.2.920-1.amzn2023.0.1.aarch64
vim-minimal-debuginfo-9.2.920-1.amzn2023.0.1.aarch64
vim-debugsource-9.2.920-1.amzn2023.0.1.aarch64
vim-debuginfo-9.2.920-1.amzn2023.0.1.aarch64
vim-enhanced-9.2.920-1.amzn2023.0.1.aarch64
xxd-debuginfo-9.2.920-1.amzn2023.0.1.aarch64
vim-minimal-9.2.920-1.amzn2023.0.1.aarch64
vim-common-9.2.920-1.amzn2023.0.1.aarch64
noarch:
vim-default-editor-9.2.920-1.amzn2023.0.1.noarch
vim-filesystem-9.2.920-1.amzn2023.0.1.noarch
vim-data-9.2.920-1.amzn2023.0.1.noarch
src:
vim-9.2.920-1.amzn2023.0.1.src
x86_64:
vim-enhanced-debuginfo-9.2.920-1.amzn2023.0.1.x86_64
xxd-debuginfo-9.2.920-1.amzn2023.0.1.x86_64
vim-debuginfo-9.2.920-1.amzn2023.0.1.x86_64
vim-debugsource-9.2.920-1.amzn2023.0.1.x86_64
vim-enhanced-9.2.920-1.amzn2023.0.1.x86_64
vim-minimal-9.2.920-1.amzn2023.0.1.x86_64
vim-minimal-debuginfo-9.2.920-1.amzn2023.0.1.x86_64
vim-common-9.2.920-1.amzn2023.0.1.x86_64
xxd-9.2.920-1.amzn2023.0.1.x86_64