USN-8246-1: Vim vulnerabilities
Michał Majchrowicz discovered that Vim’s zip plugin could overwrite
arbitrary files. An attacker could possibly use this issue to delete
sensitive data or execute arbitrary code. This issue only affected
Ubuntu 26.04 LTS. (CVE-2026-35177)
It was discovered that Vim’s netbeans interface did not properly
sanitize certain strings. An attacker could possibly use this issue to
execute arbitrary commands. This issue only affected Ubuntu 26.04 LTS.
(CVE-2026-39881)
It was discovered that Vim did not properly handle backticks in tag
filenames. An attacker could possibly use this issue to execute arbitrary
commands. (CVE-2026-41411)