[CLSA-2026:1779182780] vim: Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-19 09:26:24 UTC
Description:
- CVE-2021-4069: copy ml_get_curline() in ex_open() so a flushed line buffer is not used after vim_regexec() - CVE-2022-2000: truncate IObuff with "..." in append_command() when remaining space is below threshold - CVE-2022-3099: guard do_cmdline() breakpoint lookup with lines_ga.ga_len > current_line check - CVE-2022-1968: introduce get_line_and_copy() in find_pattern_in_path() so mark-based regex cannot invalidate the line - CVE-2022-0443: cache buf_valid() in set_curbuf() and fall back to lastbuf when buffer was wiped out - CVE-2022-1735: add check_visual_pos() and call it after every change/stop_insert so VIsual mark is clamped
Updated packages:
  • vim-X11-8.0.1763-16.el8.tuxcare.els3.x86_64.rpm
    sha:f259b2ac27f2c33ce5a2c3d06132557a62f7083510d667c07791f1ad52f1b435
  • vim-common-8.0.1763-16.el8.tuxcare.els3.x86_64.rpm
    sha:155c3788444bed4f9827f87b67214266c736ad6726eeb0190a936b58b679509e
  • vim-enhanced-8.0.1763-16.el8.tuxcare.els3.x86_64.rpm
    sha:edca673bb01d911eb2afbdf8672812faa3ff31e2d765dbcd0ac98ae170a05302
  • vim-filesystem-8.0.1763-16.el8.tuxcare.els3.noarch.rpm
    sha:0dc4225fed0ae86d30923ef6ea26bc0757ebdbe68a79f4a939dfd534ed6e9e7f
  • vim-minimal-8.0.1763-16.el8.tuxcare.els3.x86_64.rpm
    sha:2d2c7d72f46f9a691dcfbbade97e536901008b7ab0a01f53c696148736440833
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.