[CLSA-2026:1779271781] vim: Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-20 10:09:45 UTC
Description:
- CVE-2022-4292: also check win_valid_any_tab() in did_set_spelllang() after SpellFileMissing autocmd - CVE-2023-4751: reset_VIsual_and_resel() at start of ex_buffer_all() to prevent UAF on Visual mark - CVE-2023-0054: bail out of do_string_sub() when vim_regsub() returns sublen <= 0 - CVE-2022-2206: clamp cmdline_row/msg_row to Rows-1 at end of check_shellsize() - CVE-2023-5535: block_autocmds()/unblock_autocmds() around buf_contents_changed() temp-buffer life - CVE-2022-2129: tighten do_exedit() check to (textlock != 0 || curbuf_locked()) instead of curbuf_locked() only
Updated packages:
  • vim-X11-8.0.1763-19.el8.4.tuxcare.els6.x86_64.rpm
    sha:660c3c1f7f14d30115bce9beab2173d1f3b662e34bcf453968bdebc660c287ab
  • vim-common-8.0.1763-19.el8.4.tuxcare.els6.x86_64.rpm
    sha:2c7e975333f187f292d719ce5d758e3975acc489579265586d21f698bcd1776e
  • vim-enhanced-8.0.1763-19.el8.4.tuxcare.els6.x86_64.rpm
    sha:4f21c6c4c7b38ef802c1992a40fa9dc73e5c7dee6cbae39709dba2940c052f9b
  • vim-filesystem-8.0.1763-19.el8.4.tuxcare.els6.noarch.rpm
    sha:6663418f95c5cd9279aa4370cb806f40bdac649d3574a45af3e8e3867adaa805
  • vim-minimal-8.0.1763-19.el8.4.tuxcare.els6.x86_64.rpm
    sha:16fbe5dd5fc3bc90871dabc1618dd86e2a69934f76187e25e02fdda122f13f96
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.