Red Hat Updates RHEL 6 ELS Vim for 13 Vulnerabilities

P1 — VALIDATE AND UPDATEMedium to High · 4.1–8.2 (CVSS v3.1)EXPLOITATION: NOT STATED

Quick Answer

Red Hat published RHSA-2026:69128 for 13 Vim vulnerabilities in the RHEL 6 Extended Lifecycle Support Extension. Official CVSS v3.1 scores range from 4.1 Medium to 8.2 High; the fixed Vim build is 7.4.629-5.el6_10.4.

Update Entitled RHEL 6 ELS Vim Packages

What to do now: Identify RHEL 6 ELS Extension systems and installed Vim subpackages, apply the advisory build from the entitled repository, and validate editor, automation, recovery, and untrusted-file workflows.

Open the authoritative advisory

Last verified: 2026-09-21 UTC. Recheck the current authoritative advisory and entitled repository before changing production.

Scope And Authority

Product scopeRHEL 6 Extended Lifecycle Support Extension Vim
AdvisoryRHSA-2026:69128
CVEsCVE-2026-28417, CVE-2026-28421, CVE-2026-34982, CVE-2026-35177, CVE-2026-41411, CVE-2026-46483, CVE-2026-47162, CVE-2026-47167, CVE-2026-52858, CVE-2026-55693, CVE-2026-57455, CVE-2026-57456, CVE-2026-59858
Authoritative release date2026-09-21 03:04:51 UTC
Authority revision date2026-09-21 03:07:06 UTC
Affected versionsRHEL 6 ELS Extension Vim packages before 7.4.629-5.el6_10.4
Fixed versionvim 7.4.629-5.el6_10.4
CVSS base score4.1–8.2 (CVSS v3.1)
CVSS severityMedium to High
Exploitation statusNot stated by Red Hat; no exploitation claim is inferred.

What Changed

The advisory covers denial of service, information disclosure, and multiple command- or code-execution paths in Vim features including netrw, modelines, tags, archive handling, directory handling, and completion. Conditions vary by CVE and often require opening or processing crafted content; the advisory does not make every Vim installation equally exposed.

What To Validate Now

  1. Inventory. Locate entitled RHEL 6 ELS Extension systems and every installed Vim package, including minimal, enhanced, common, and X11 variants used interactively or by automation.
  2. Establish applicability. Confirm the ELS Extension stream and exact NVR; identify workflows that open untrusted files, archives, repositories, modelines, tags, directories, or remote content.
  3. Remediate. Update the affected Vim packages to 7.4.629-5.el6_10.4 through the supported Red Hat repository and remove unused variants where approved.
  4. Validate. Confirm each installed Vim subpackage NVR, test representative editing and automation paths, and preserve relevant security and change-management evidence.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

RHEL 6 ELS is a specific entitlement and lifecycle state. Validate dependencies and recovery access before changing legacy systems, and do not substitute an upstream Vim version for Red Hat's package NVR mapping.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, source advisory revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.