Release date:
2026-09-15 09:33:17 UTC
Description:
- CVE-2026-73072: fix heap buffer overflow in set_sofo(); reset sl_sal_first[] before the SN_SOFO
counting loop, since a preceding SN_SAL section may have set its entries to -1 via set_sal_first(),
making the loop under-count colliding multi-byte characters and allocate an undersized list
(src/spellfile.c, upstream patch 9.2.0846)
- CVE-2026-73076: fix arbitrary code execution via a crafted .VimballRecord file; refuse to extract
a member named .VimballRecord, record deletions with string() instead of raw quote interpolation,
and execute only whitelisted call delete() entries in vimball#RmVimball()
(runtime/autoload/vimball.vim, upstream patch 9.2.0847)
- CVE-2026-73078: fix Ex command injection in the netrw bookmark and history menus; add the Ex
separator | to g:netrw_menu_escape, escape the :e targets with fnameescape(), and quote the
netrw#MakeTgt() arguments with string() (runtime/autoload/netrw.vim, upstream patch 9.2.0840)
Updated packages:
-
vim-X11-8.0.1763-19.el8.4.tuxcare.els23.x86_64.rpm
sha:068998d486928b527c0866230c968292dab8f60f94dc595a1f653576143a837d
-
vim-common-8.0.1763-19.el8.4.tuxcare.els23.x86_64.rpm
sha:c34ca94993f8f051a31aeef74cf4966b275cee83d142f1fb7237dabd7405c4c4
-
vim-enhanced-8.0.1763-19.el8.4.tuxcare.els23.x86_64.rpm
sha:2e89994c8bb22118b76e009582b7315dd924503222456512ea9b737a863bf92b
-
vim-filesystem-8.0.1763-19.el8.4.tuxcare.els23.noarch.rpm
sha:d78a304fb88a836e389d0b8a544263e36870f2a04793810a68ceaa8c68c034fe
-
vim-minimal-8.0.1763-19.el8.4.tuxcare.els23.x86_64.rpm
sha:5260987c6b463e6ae840860c675f0e29def5ff78bd9a60222af976dbe61f477c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.