[CLSA-2026:1786542733] vim: Fix of CVE-2026-25749
Type:
security
Severity:
Important
Release date:
2026-08-12 13:52:24 UTC
Description:
- CVE-2026-25749: fix buffer overflow in 'helpfile' option handling in get_tagfname(); replace unbounded STRCPY of p_hf with a bounded vim_strncpy leaving room for the "tags" suffix (src/tag.c). Adds a functional test
CVEs fixed:
Updated packages:
  • vim-X11-9.0.2153-1.amzn2.0.9.tuxcare.els2.x86_64.rpm
    sha:eb47b1f725154d46ae57def337b58df426ed5897cd7d51398faf1e3c31d7d6d0
  • vim-common-9.0.2153-1.amzn2.0.9.tuxcare.els2.x86_64.rpm
    sha:457808f799b31dfbcc495197859ac30886a57734b7f803dec41c961d81ca98d1
  • vim-data-9.0.2153-1.amzn2.0.9.tuxcare.els2.noarch.rpm
    sha:c78d55983eabd9014746c0ed0fb33e081651c66c990b1f98b121e83d1d7c0b67
  • vim-enhanced-9.0.2153-1.amzn2.0.9.tuxcare.els2.x86_64.rpm
    sha:3cff1e1050b213d35fbbdd5407d8a790eeb5cc51e8a55b165d399445cf0b29f1
  • vim-filesystem-9.0.2153-1.amzn2.0.9.tuxcare.els2.noarch.rpm
    sha:8b24017f9fddaa1a44d0db32bc5c017f4046d2d41eba207b450b03224fc49aa5
  • vim-minimal-9.0.2153-1.amzn2.0.9.tuxcare.els2.x86_64.rpm
    sha:c99c19e3b7c6beffcec9d117513697622812a6b910058dd7e766810b6c2d407d
  • xxd-9.0.2153-1.amzn2.0.9.tuxcare.els2.x86_64.rpm
    sha:107939abcd8cffdfa2f9c043665456594cf245fb9cade90bc6f417ca374f6650
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.