[CLSA-2026:1779694105] Fix CVE(s): CVE-2026-42307
Type:
security
Severity:
Low
Release date:
2026-05-25 07:28:29 UTC
Description:
* SECURITY UPDATE: fix shell-injection in netrw via crafted sftp:// and file:// URLs by escaping the tempfile name and restricting the filename-suffix regex to word characters (runtime/autoload/netrw.vim, upstream patch 9.2.0383) - debian/patches/CVE-2026-42307.patch: fix shell-injection in netrw via crafted sftp:// and file:// URLs by escaping the tempfile name and restricting the filename-suffix regex to word characters (runtime/autoload/netrw.vim, upstream patch 9.2.0383) - CVE-2026-42307
Updated packages:
  • vim_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:61c5d423dda368700cce11afc012114bc4662b1c
  • vim-athena_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:8352c6130a402f4b42e8bba0f596d15ff8f83044
  • vim-athena-py2_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:6d2608ba6c48d5e804fb21fd4e9862b540387295
  • vim-common_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:b99ff7c47110d22eb206166968aaca14e89ad166
  • vim-doc_7.4.1689-3ubuntu1.5+tuxcare.els64_all.deb
    sha:b28298e7334f2d4f089c563154571b53bc9c9029
  • vim-gnome_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:ba8f8272a8b3002bc2f5b09af3d6f86a1eb0a55a
  • vim-gnome-py2_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:686e7dc0970aa15fc4a2cfb3ab714fab0e00ee7d
  • vim-gtk_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:a60c5747c8ace4c8e4fda11ccff65fcb87be3b9c
  • vim-gtk-py2_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:fffa6ad07972472036353412a4eaa15cf682b9f1
  • vim-gtk3_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:9744f34ba73f194bcc06cfb7524e5428ec9b6b65
  • vim-gtk3-py2_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:481b76d181e3fd86acaa2e3172480ea6077e53b0
  • vim-gui-common_7.4.1689-3ubuntu1.5+tuxcare.els64_all.deb
    sha:c3766fdf439e6984262a10f33ee23c239a934ff6
  • vim-nox_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:a4e8ee3280eacddad04f8c3396f53aab32695961
  • vim-nox-py2_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:57376d85e26191f7f5a9c8e926ecf883d06bfbf1
  • vim-runtime_7.4.1689-3ubuntu1.5+tuxcare.els64_all.deb
    sha:1002e06aa61c548bfe06b95da38aba17de862ef0
  • vim-tiny_7.4.1689-3ubuntu1.5+tuxcare.els64_amd64.deb
    sha:223cbb3fc5279841eb315c9ae286531edd4c6aaa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.