[CLSA-2026:1789206875] Fix of 10 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-12 09:54:56 UTC
Description:
* SECURITY UPDATE: out-of-bounds read when undo makes the Visual area invalid - debian/patches/CVE-2022-0368.patch: correct the Visual area after undo in src/undo.c, add test to src/testdir/test_visual.vim. - CVE-2022-0368 * SECURITY UPDATE: buffer overflow in the spell suggest code after invalid bytes are added with :spellgood - debian/patches/CVE-2022-1621.patch: reject words that are not a valid utf-8 string in store_word() and spell_add_word() in src/spellfile.c, add the E1280 message to src/errors.h, build utf_valid_string() when FEAT_SPELL is enabled in src/mbyte.c, add test to src/testdir/test_spell_utf8.vim. - CVE-2022-1621 * SECURITY UPDATE: buffer over-read on a trailing escape character in quote text objects - debian/patches/CVE-2022-1629.patch: check for NUL after the escape character in find_next_quote() in src/textobject.c, add test to src/testdir/test_textobjects.vim. - CVE-2022-1629 * SECURITY UPDATE: heap buffer overflow when text is changed in Visual mode - debian/patches/CVE-2022-1735.patch: revalidate the Visual start position after a buffer change; add check_visual_pos() in src/misc2.c, src/proto/misc2.pro and call it from changed_common() in src/change.c and stop_insert() in src/edit.c; add test to src/testdir/test_visual.vim. - CVE-2022-1735 * SECURITY UPDATE: use-after-free when searching for a pattern in path - debian/patches/CVE-2022-1968.patch: copy the buffer line into the file_line buffer before matching in find_pattern_in_path(), in src/search.c; add test in src/testdir/test_tagjump.vim. - CVE-2022-1968 * SECURITY UPDATE: heap buffer over-read with a line-zero address ("0;'(") - debian/patches/CVE-2022-2182.patch: check that the cursor column is valid for line one when the address is zero, in parse_cmd_address() in src/ex_docmd.c; add regression test in src/testdir/test_cmdline.vim. - CVE-2022-2182 * SECURITY UPDATE: out-of-bounds read with a menu item consisting of only a modifier - debian/patches/CVE-2022-2257.patch: check for NUL before advancing past the end of the string in str2special() in src/message.c, add test to src/testdir/test_menu.vim. - CVE-2022-2257 * SECURITY UPDATE: Ex command injection in netrw remote file browsing - debian/patches/CVE-2026-55895.patch: use fnameescape() on the buffer name before passing it to :execute in s:NetrwBrowse() in runtime/autoload/netrw.vim. - CVE-2026-55895 * SECURITY UPDATE: arbitrary code execution via a crafted doc string in python omni-completion - debian/patches/CVE-2026-57456.patch: quote reconstructed doc strings with repr() instead of pasting them between literal triple quotes, in the Scope, Class and Function get_code() methods in runtime/autoload/python3complete.vim and runtime/autoload/pythoncomplete.vim. - CVE-2026-57456 * SECURITY UPDATE: arbitrary Ex command execution during C omni-completion - debian/patches/CVE-2026-59858.patch: escape the tags typeref/typename field with escape(typename, '/\') before interpolating it into the :vimgrep pattern in s:StructMembers() in runtime/autoload/ccomplete.vim; add test in src/testdir/test_plugin_ccomplete.vim, src/testdir/Make_all.mak. - CVE-2026-59858 * Fix the failing Test_terminal_cwd() - debian/patches/fix-Test_terminal_cwd.patch: join two lines to prevent fail on a long pathname * Fix the failing Test_quit_long_message() - debian/patches/fix-Test_quit_long_message.patch: wait for the more prompt instead of the ruler and dump 10 screen rows, so a long build pathname in the error message does not overflow the test terminal * Fix the tests that fail when the package is built as root - debian/patches/fix-tests-run-as-root.patch: guard the four permission-dependent tests with CheckNotRoot, splitting the read-only cases of Test_redir_cmd() and Test_helptag_cmd() into their own tests * Fix the tests that fail on the timing of the arm builders - debian/patches/fix-mouse-click-test-timing.patch: raise 'mousetime' in the two multiple-click mouse tests - debian/patches/fix-tests-tolerate-flaky-giveup.patch: add $TEST_MAY_FAIL_FLAKY, set by debian/rules on the non-amd64 targets, to report a given-up flaky test instead of failing the build - debian/patches/fix-tests-stray-swapfiles.patch: drop leftover scratch swap files between test files, so E325 cannot cascade
Updated packages:
  • vim_8.2.2434-3+deb11u3+tuxcare.els3_amd64.deb
    sha:2f9b74c2038ac8279865c6634aeb78222eb79d71
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els3_amd64.deb
    sha:bc636f9b7647a44050b7ebc3a665540b53830df8
  • vim-common_8.2.2434-3+deb11u3+tuxcare.els3_all.deb
    sha:cbc4a0ae5eaec7600335e08e30b64418e7c3a179
  • vim-doc_8.2.2434-3+deb11u3+tuxcare.els3_all.deb
    sha:cf663ca38c0e6c12a1f90f39bfa46d73e79e5874
  • vim-gtk_8.2.2434-3+deb11u3+tuxcare.els3_all.deb
    sha:5a6e7261db220f0515d06e7bdd17043d2905666a
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els3_amd64.deb
    sha:ac9ebfea9238077fb0be50f1503384682c11324a
  • vim-gui-common_8.2.2434-3+deb11u3+tuxcare.els3_all.deb
    sha:68d26e922102dfdad9be082a113dfb5b6de81368
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els3_amd64.deb
    sha:bad169d6ab4edf120e46f0b294111eee3d7f0699
  • vim-runtime_8.2.2434-3+deb11u3+tuxcare.els3_all.deb
    sha:4fcd820b94dc6faae699eefa153f56b07e261775
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els3_amd64.deb
    sha:e1c05798f06b527dc249e7d74534129f0cb41867
  • xxd_8.2.2434-3+deb11u3+tuxcare.els3_amd64.deb
    sha:9abebee58277c7dd4917b0e8a877e59ecbca11a4
  • vim_8.2.2434-3+deb11u3+tuxcare.els3_arm64.deb
    sha:d743b9fc901b79adfa7aa0770ca019e7681909de
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els3_arm64.deb
    sha:c6cfadb33994b152fa27978e0bd6a3964e42b016
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els3_arm64.deb
    sha:fa972438b6fdba18efab2f6502797b0c8d10a372
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els3_arm64.deb
    sha:00fb23ff6167a02cb6b2c4dda75a09cef6e30eca
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els3_arm64.deb
    sha:17a8f9900050e68ff6935f37995d92ae9d5bd548
  • xxd_8.2.2434-3+deb11u3+tuxcare.els3_arm64.deb
    sha:0ee653608d33a5992ac90cf48700c5f20f8f54aa
  • vim_8.2.2434-3+deb11u3+tuxcare.els3_armel.deb
    sha:2fc0ff2dba005b9fdc75704f74157254e3c21c44
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els3_armel.deb
    sha:b4fbfc2d493d026abb1399c4873e633245160f61
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els3_armel.deb
    sha:871b1fce97b986c3d81e88a1cd49913670e7a641
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els3_armel.deb
    sha:5fc5c73ca751a7e4e7b15d8b68289b5324847f14
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els3_armel.deb
    sha:8384d03147c8e5d3accd73c77a7524a4164b1ed9
  • xxd_8.2.2434-3+deb11u3+tuxcare.els3_armel.deb
    sha:a277b7e403c9236a372c129d5eb51c56788b7836
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.