Red Hat Updates RHEL 6 ELS Vim for 13 Vulnerabilities
Quick Answer
Red Hat published RHSA-2026:69128 for 13 Vim vulnerabilities in the RHEL 6 Extended Lifecycle Support Extension. Official CVSS v3.1 scores range from 4.1 Medium to 8.2 High; the fixed Vim build is 7.4.629-5.el6_10.4.
Update Entitled RHEL 6 ELS Vim Packages
What to do now: Identify RHEL 6 ELS Extension systems and installed Vim subpackages, apply the advisory build from the entitled repository, and validate editor, automation, recovery, and untrusted-file workflows.
Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.
Scope And Authority
| Product scope | RHEL 6 Extended Lifecycle Support Extension Vim |
|---|---|
| Advisory | RHSA-2026:69128 |
| CVEs | CVE-2026-28417, CVE-2026-28421, CVE-2026-34982, CVE-2026-35177, CVE-2026-41411, CVE-2026-46483, CVE-2026-47162, CVE-2026-47167, CVE-2026-52858, CVE-2026-55693, CVE-2026-57455, CVE-2026-57456, CVE-2026-59858 |
| Authoritative release date | 2026-09-21 03:04:51 UTC |
| Authority revision date | 2026-09-21 03:07:06 UTC |
| Affected versions | RHEL 6 ELS Extension Vim packages before 7.4.629-5.el6_10.4 |
| Fixed version | vim 7.4.629-5.el6_10.4 |
| CVSS base score | 4.1–8.2 (CVSS v3.1) |
| CVSS severity | Medium to High |
| Exploitation status | Not stated by Red Hat; no exploitation claim is inferred. |
What Changed
The advisory covers denial of service, information disclosure, and multiple command- or code-execution paths in Vim features including netrw, modelines, tags, archive handling, directory handling, and completion. Conditions vary by CVE and often require opening or processing crafted content; the advisory does not make every Vim installation equally exposed.
What To Validate Now
- Inventory. Locate entitled RHEL 6 ELS Extension systems and every installed Vim package, including minimal, enhanced, common, and X11 variants used interactively or by automation.
- Establish applicability. Confirm the ELS Extension stream and exact NVR; identify workflows that open untrusted files, archives, repositories, modelines, tags, directories, or remote content.
- Remediate. Update the affected Vim packages to 7.4.629-5.el6_10.4 through the supported Red Hat repository and remove unused variants where approved.
- Validate. Confirm each installed Vim subpackage NVR, test representative editing and automation paths, and preserve relevant security and change-management evidence.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
RHEL 6 ELS is a specific entitlement and lifecycle state. Validate dependencies and recovery access before changing legacy systems, and do not substitute an upstream Vim version for Red Hat's package NVR mapping.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

