Echo: vim: security update to 2:9.1.1230-1

medium Tenable Self-Hosted Container Security Plugin ID 465392

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages
using the `:redir` ex command to register, variables and files. It also allows to show the contents of
registers using the `:registers` or `:display` ex command. When redirecting the output of `:display` to a
register, Vim will free the register content before storing the new content in the register. Now when
redirecting the `:display` command to a register that is being displayed, Vim will free the content while
shortly afterwards trying to access it, which leads to a use-after-free. Vim pre 9.1.1115 checks in the
ex_display() function, that it does not try to redirect to a register while displaying this register at
the same time. However this check is not complete, and so Vim does not check the `+` and `*` registers
(which typically donate the X11/clipboard registers, and when a clipboard connection is not possible will
fall back to use register 0 instead. In Patch 9.1.1115 Vim will therefore skip outputting to register zero
when trying to redirect to the clipboard registers `*` or `+`. Users are advised to upgrade. There are no
known workarounds for this vulnerability. (CVE-2025-26603)

Solution

Update the vim library and its related packages to version 2:9.1.1230-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2025-26603

Plugin Details

Severity: Medium

ID: 465392

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.36

CVSS v2

Risk Factor: Low

Base Score: 3.5

Temporal Score: 2.6

Vector: CVSS2#AV:L/AC:H/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2025-26603

CVSS v3

Risk Factor: Medium

Base Score: 4.2

Temporal Score: 3.7

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/15/2025

Vulnerability Publication Date: 2/18/2025

Reference Information

CVE: CVE-2025-26603

IAVA: 2025-A-0128-S