[CLSA-2026:1790180200] Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-23 16:16:56 UTC
Description:
* SECURITY UPDATE: heap buffer overflow/underflow scrolling without valid screen - debian/patches/CVE-2022-2206.patch: re-clamp cmdline_row/msg_row after a terminal resize shrinks Rows, in check_shellsize() in src/term.c. - CVE-2022-2206 * SECURITY UPDATE: illegal memory access when 'spellfile' has a very long file name - debian/patches/CVE-2021-3928.patch: check that preword is not empty before backing up a pointer into it in suggest_trie_walk() in src/spellsuggest.c. - CVE-2021-3928 * SECURITY UPDATE: using freed memory with ]d/[d/]D/[D/]i/[i/]I/[I - debian/patches/CVE-2022-1898.patch: copy the identifier found under the cursor before passing it to find_pattern_in_path(), in nv_brackets() in src/normal.c. - CVE-2022-1898 * SECURITY UPDATE: using freed memory when 'spellfile' triggers a SpellFileMissing autocmd that wipes out the buffer - debian/patches/CVE-2022-3352.patch: disallow deleting the current buffer while spell_load_lang() runs, in src/spell.c. - CVE-2022-3352 * SECURITY UPDATE: use-after-free with autocommands that change the window layout while editing another file - debian/patches/CVE-2023-4733.patch: invalidate the old window pointer after autocommands may have closed it, in do_ecmd() in src/ex_cmds.c. - CVE-2023-4733
Updated packages:
  • vim_8.2.2434-3+deb11u3+tuxcare.els13_amd64.deb
    sha:9b78c7e8e310c5506b090a30112b3bc65c954966
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els13_amd64.deb
    sha:eba87fc137508e645197fb90346847d70a8e403d
  • vim-common_8.2.2434-3+deb11u3+tuxcare.els13_all.deb
    sha:0196afa596bf117804c072730e218bfb712a440b
  • vim-doc_8.2.2434-3+deb11u3+tuxcare.els13_all.deb
    sha:ca46640e20138b5a19de1bfb777619c576e05743
  • vim-gtk_8.2.2434-3+deb11u3+tuxcare.els13_all.deb
    sha:06df76064fc58c4cc60145b34c3ce79195f8b8e0
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els13_amd64.deb
    sha:c74da1e878cbf397738b75dd76db9be7549fda55
  • vim-gui-common_8.2.2434-3+deb11u3+tuxcare.els13_all.deb
    sha:ca74421b52973c3c537ad0ebc5275a386b213898
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els13_amd64.deb
    sha:a6b1e0f27af8c0868ecb89fb50a2ab0843ed13a1
  • vim-runtime_8.2.2434-3+deb11u3+tuxcare.els13_all.deb
    sha:9f5f361b26bb92ca3669b193c6f57f22a23dfb87
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els13_amd64.deb
    sha:8cb276d31d1e2a620826d316eab89f639f2c8e96
  • xxd_8.2.2434-3+deb11u3+tuxcare.els13_amd64.deb
    sha:a0c3124a4e5112dbffd385de7d056bcb41a54d23
  • vim_8.2.2434-3+deb11u3+tuxcare.els13_arm64.deb
    sha:78dceca16cbc7513656cf47f6cdda88c31b605e8
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els13_arm64.deb
    sha:ef0ea4260a160020f5b9744d4d9f715d994bcbd4
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els13_arm64.deb
    sha:118d7f2bfbf48912b2314c54a26d02a3a2194337
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els13_arm64.deb
    sha:669799acd835f7204864ce1083a0dc3bd0a561ed
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els13_arm64.deb
    sha:15308df79d3b167987498156161fbd387c43677c
  • xxd_8.2.2434-3+deb11u3+tuxcare.els13_arm64.deb
    sha:181703106bc2159db3d8374c55e9416d0aedb789
  • vim_8.2.2434-3+deb11u3+tuxcare.els13_armel.deb
    sha:2ff989aeb22a2e752d44b740a9da1eba7fc1490b
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els13_armel.deb
    sha:de775e127bd7bd66f8c07413c1fd9ee0255dcba0
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els13_armel.deb
    sha:3fac90b27e80f6ee989ed86aa0c53ea3f69613ac
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els13_armel.deb
    sha:ed00b895bdc28187e16104079bf5a90967c1ea38
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els13_armel.deb
    sha:e590867cc59a9822e533a9499dd475687b2978cc
  • xxd_8.2.2434-3+deb11u3+tuxcare.els13_armel.deb
    sha:14c624628b14694ad9dca09029700ae43fe69e6f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.