[CLSA-2026:1779583115] vim: Fix of CVE-2026-46483
Type:
security
Severity:
Important
Release date:
2026-05-25 07:23:17 UTC
Description:
- CVE-2026-46483: fix command injection in tar plugin Vimuntar() when decompressing .tgz archives by passing the {special} flag to shellescape() (upstream vim 9.2.0479)
Updated packages:
  • vim-X11-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:fe4ed826ef3d666fee58e245aef8876cd60ab7587c7a932ac11f9ecea7a1d61c
  • vim-common-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:302f8635cf380d8db293aa199d11a97906c92f21b09b94d99180f628e6cdf40e
  • vim-enhanced-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:ccdf362a783bbe2fb471b8e5aef252bc1b206a38cd55a71430302d0368e73593
  • vim-filesystem-8.0.1763-16.el8.tuxcare.els17.noarch.rpm
    sha:ca9dfdaa01be20eed47486b393a758552713b1750522f5fc9af8da8be5624dbe
  • vim-minimal-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:4fd640614181c089640044c924df94fdc11f1731bea436a5f2acf1fbce32bcdc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.