[CLSA-2026:1779214181] vim: Fix of 4 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-05-19 18:09:50 UTC
Description:
- CVE-2022-3278: fix crash when using NUL in buffer that uses :source; don't get a next line when skipping over NL in eval_next_non_blank() (eval.c, upstream patch 9.0.0552) - CVE-2023-48234: fix overflow when getting count for normal z command; break out of nv_zet() count loop when n > LONG_MAX/10 (normal.c, upstream patch 9.0.2109) - CVE-2023-48236: fix overflow in get_number() when using z= with a large count; return 0 when n > INT_MAX/10 (misc1.c, upstream patch 9.0.2111) - CVE-2025-26603: fix use-after-free in str_to_reg() when redirecting :display to a clipboard register; skip the active redir register including the * and + clipboard fallbacks to register 0 (register.c, upstream patch 9.1.1115)
Updated packages:
  • vim-X11-8.2.2637-22.el9_6.1.tuxcare.els25.x86_64.rpm
    sha:1c748768233afb324052c50d30c68fcf21a00587b8eb2d03bd1a56d680f04b8a
  • vim-common-8.2.2637-22.el9_6.1.tuxcare.els25.x86_64.rpm
    sha:b3e34a1e7f6da481f75e4f0f376fb2fb3cb5948836131070c9f158de9261b8d8
  • vim-enhanced-8.2.2637-22.el9_6.1.tuxcare.els25.x86_64.rpm
    sha:e893b3ac15b0d263178bf4b4ae8402505f1416d45664e3c5a0cbe9d6288e21d4
  • vim-filesystem-8.2.2637-22.el9_6.1.tuxcare.els25.noarch.rpm
    sha:450cb08415f4adcd21fa21ac493b21372a9c5ea5e70f37da224795ec71a03623
  • vim-minimal-8.2.2637-22.el9_6.1.tuxcare.els25.x86_64.rpm
    sha:3135762b731262d147aa300b806b6aed61ea2c3097580cb21436581f40db8222
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.