Alpine: gvim, multiple vim packages, xxd: security update to 9.2.0219-r0

high Tenable Self-Hosted Container Security Plugin ID 439105

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection
vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n)
in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This
vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.
(CVE-2026-33412)

Solution

Update the gvim library and its related packages to version 9.2.0219-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-33412

Plugin Details

Severity: High

ID: 439105

Version: Revision 1.10

Type: Local

Published: 3/21/2026

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.88

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-33412

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2026-33412