[CLSA-2026:1779583844] vim: Fix of CVE-2026-46483
Type:
security
Severity:
Important
Release date:
2026-05-25 21:07:24 UTC
Description:
- CVE-2026-46483: fix command injection in tar plugin Vimuntar() when decompressing .tgz archives by passing the {special} flag to shellescape() (upstream vim 9.2.0479)
Updated packages:
  • vim-X11-8.0.1763-19.el8.4.tuxcare.els16.x86_64.rpm
    sha:32ed1a7875fa588e6b9a646ba3b92e5a5d0600848775a5653e681bf620017a5b
  • vim-common-8.0.1763-19.el8.4.tuxcare.els16.x86_64.rpm
    sha:8907efddda53e2b0a6985fbec15080fd65a653df0959a957311fc3da7240fb43
  • vim-enhanced-8.0.1763-19.el8.4.tuxcare.els16.x86_64.rpm
    sha:ff95ffc2d8e9963492ab989dffb038c32aabed977d5814eea21b3ea0a43d5204
  • vim-filesystem-8.0.1763-19.el8.4.tuxcare.els16.noarch.rpm
    sha:befd6bb2965fb657c7637612d2e89036d838d757cffe09f6b60ff2f5c1484a7e
  • vim-minimal-8.0.1763-19.el8.4.tuxcare.els16.x86_64.rpm
    sha:7562d92ed148e7e4c69cbcd954f09c41f964d16e2087d374f9b16708fc7a0aae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.