[NetSIG] vim zero-day (fixed) ... but not emacs

Craig Miller cvmiller at gmail.com
Sun Apr 26 16:48:49 PDT 2026


Mark,

On MX Linux vi is (round-about) connect to vim.tiny, which vim is also 
linked to. So there is no difference between vi and vim.

  /usr/bin$ ls -l vi*
lrwxrwxrwx 1 root root      20 May  4  2023 vi -> /etc/alternatives/vi
lrwxrwxrwx 1 root root      22 Feb 14  2023 view -> /etc/alternatives/view
-rwxr-xr-x 1 root root   32288 Feb 28  2020 viewres
lrwxrwxrwx 1 root root       8 Sep 14  2024 vim -> vim.tiny
-rwxr-xr-x 1 root root    1082 Jul 14  2024 vimdot
-rwxr-xr-x 1 root root 1629584 Feb 15  2025 vim.tiny
-rwxr-xr-x 1 root root     239 Dec  8  2022 virtualenv
cvmiller at ohe /usr/bin$
cvmiller at ohe /usr/bin$
cvmiller at ohe /usr/bin$ ls -l /etc/alternatives/vi
lrwxrwxrwx 1 root root 17 May  4  2023 /etc/alternatives/vi -> /usr/bin/vim.tiny

On Alpine Linux, vi is part of busybox (a multicall binary), and there 
is no vim by default.

On PiOS (bookworm), there is vi, and no vim (be default).

So I guess the answer is: "it depends"

Craig....

On 4/26/26 12:14, Mark G. wrote:
> Nice that it is patched.  I just noticed, however, that FreeBSD
> ships plain old vi, not vim.  Is vi a default in Linux, or is
> it vim instead?  Curious, are there essential features that
> vim has that makes it more useful than vi?
>
>
>
>
> On 4/24/26 07:49, Greg H wrote:
>> Here's the vim zero-day discussed last night:
>>
>> https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html 
>> <https://www.csoonline.com/article/4153288/vim-and-gnu-emacs-claude-code-helpfully-found-zero-day-exploits-for-both.html> 
>>
>>
>> /“An attacker who can deliver a crafted file to a victim achieves 
>> arbitrary command execution with the privileges of the user running 
>> Vim,” Vim maintainers noted in their security advisory 
>> <https://github.com/vim/vim/security/advisories/ 
>> GHSA-2gmj-rpqf-pxvh>. “The attack requires only that the victim opens 
>> the file; no further interaction is needed.”/
>>
>> I forgot to mention an emacs flaw was also discovered.
>>
>> Greg
>>
>>
>
-- 
IPv6 is the future, the future is here
http://ipv6hawaii.org/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://vicpimakers.ca/pipermail/netsig_vicpimakers.ca/attachments/20260426/bde40048/attachment.htm>


More information about the NetSIG mailing list