[CLSA-2026:1779582830] vim: Fix of CVE-2026-46483
Type:
security
Severity:
Important
Release date:
2026-05-24 00:33:54 UTC
Description:
- CVE-2026-46483: fix command injection in tar plugin Vimuntar() when decompressing .tgz archives by passing the {special} flag to shellescape() (upstream vim 9.2.0479)
Updated packages:
  • vim-X11-8.2.2637-22.el9_6.1.tuxcare.els31.x86_64.rpm
    sha:019266cee1104e800fbf2e7f412eb6908d5c023efe2468402b3cd689117bbe26
  • vim-common-8.2.2637-22.el9_6.1.tuxcare.els31.x86_64.rpm
    sha:62c7e195f172bb525de3b2cb30ac2bbf2d85da7a95b5b476fc10a632d317198e
  • vim-enhanced-8.2.2637-22.el9_6.1.tuxcare.els31.x86_64.rpm
    sha:1b51fd470d7f3be755deeabf9339a7289e26457e3ad9cc94775448b2e479f447
  • vim-filesystem-8.2.2637-22.el9_6.1.tuxcare.els31.noarch.rpm
    sha:592bbbb1367386bfe7c5390098af77d8bafd6ea4834269fd9ed2fc0b661d255f
  • vim-minimal-8.2.2637-22.el9_6.1.tuxcare.els31.x86_64.rpm
    sha:14b4f9bf8cfe5a617844bb1172a0fc052b97bf552f464b106b46611cdc08ba64
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.