Release date:
2026-09-28 09:07:12 UTC
Description:
* SECURITY UPDATE: heap buffer over-read scanning for quote text objects
with a stale Visual selection
- debian/patches/CVE-2022-2124.patch: add a NUL-boundary check to the
existing-Visual-selection quote-scan loop in current_quote() in
src/textobject.c.
- CVE-2022-2124
* SECURITY UPDATE: use-after-free using a mark position in a regexp
- debian/patches/CVE-2021-3974.patch: refetch the current line under
REG_MULTI after a mark lookup may have flushed it, in the
NFA_MARK/NFA_MARK_GT/NFA_MARK_LT handling in src/regexp_nfa.c.
- CVE-2021-3974
* SECURITY UPDATE: heap buffer over-read using z= in Visual mode beyond
the end of the line
- debian/patches/CVE-2022-0943.patch: clamp badlen to the actual line
length in spell_suggest() in src/spellsuggest.c; the comparison is
taken in its post-8.2.4565 form, folding in upstream's correction
that casts both operands to int, because without it the subtraction
is evaluated in size_t and underflows, leaving the clamp a no-op.
- CVE-2022-0943
* SECURITY UPDATE: use-after-free reading a buffer for 'diff' without
blocking autocommands
- debian/patches/CVE-2023-5535.patch: block autocommands around the
dummy-buffer readfile() in buf_contents_changed() in src/buffer.c.
- CVE-2023-5535
* SECURITY UPDATE: use-after-free when 'tagfunc' wipes out the buffer
holding 'complete'
- debian/patches/CVE-2022-3297.patch: make a copy of 'complete' instead
of aliasing the option value, revalidate curbuf after the completion
callback, and validate the cursor line, in src/insexpand.c and
src/move.c; the src/move.c hunk is taken in its post-9.0.0581 form,
folding in upstream's same-day follow-up that clamps only the cursor
line, because clamping the column there breaks incsearch at end of
line.
- CVE-2022-3297
Updated packages:
-
vim_8.2.2434-3+deb11u3+tuxcare.els14_amd64.deb
sha:951eae6d44def649bf0220d8bbb8a95f6e97e668
-
vim-athena_8.2.2434-3+deb11u3+tuxcare.els14_amd64.deb
sha:2a6b6cb2f6820c1af6eeabb273b9422c2a835eaf
-
vim-common_8.2.2434-3+deb11u3+tuxcare.els14_all.deb
sha:182fb23659aa574f7bc0b708d54f1592aa82cc21
-
vim-doc_8.2.2434-3+deb11u3+tuxcare.els14_all.deb
sha:916b5c8c9d3e882b7e8d7639892bf440c42a65b9
-
vim-gtk_8.2.2434-3+deb11u3+tuxcare.els14_all.deb
sha:f732eeec936cadf9686466e413f0bae47b1d7253
-
vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els14_amd64.deb
sha:a4b131d88d6337ef613514926dd6786ff9e8833e
-
vim-gui-common_8.2.2434-3+deb11u3+tuxcare.els14_all.deb
sha:39bc998ae992f26c03d16e0ccf6a6706918e5bd6
-
vim-nox_8.2.2434-3+deb11u3+tuxcare.els14_amd64.deb
sha:f44f4c6d4977691f2f6e252a77ca12b37485c1a0
-
vim-runtime_8.2.2434-3+deb11u3+tuxcare.els14_all.deb
sha:09620e2360db6a72692b130c5c1a3e9861fbaed7
-
vim-tiny_8.2.2434-3+deb11u3+tuxcare.els14_amd64.deb
sha:9213f2109b88f384988f5a88ab025d2a8f90ddfc
-
xxd_8.2.2434-3+deb11u3+tuxcare.els14_amd64.deb
sha:e1d5eb6b379a7fa4c18d2aed2f3c905859acacd1
-
vim_8.2.2434-3+deb11u3+tuxcare.els14_arm64.deb
sha:d6118801a30c3390effceac58439746e23b7492f
-
vim-athena_8.2.2434-3+deb11u3+tuxcare.els14_arm64.deb
sha:a51087fca532aa0799ca2f1ef1ae3e3c27294084
-
vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els14_arm64.deb
sha:32f96a660572efd51b343581601c49d7c1feb0b2
-
vim-nox_8.2.2434-3+deb11u3+tuxcare.els14_arm64.deb
sha:b771ff07d2690f757e13de71fa3c1b22cd3423cd
-
vim-tiny_8.2.2434-3+deb11u3+tuxcare.els14_arm64.deb
sha:e08cf32c7d2ccd8b73d7d62fb9c3f0b032eedd98
-
xxd_8.2.2434-3+deb11u3+tuxcare.els14_arm64.deb
sha:07fec8924ef26c72bcbdcb8faa88e7223c3b8ff6
-
vim_8.2.2434-3+deb11u3+tuxcare.els14_armel.deb
sha:4dadc317a9892f215cdfcbf139efb4fdea4c36fa
-
vim-athena_8.2.2434-3+deb11u3+tuxcare.els14_armel.deb
sha:bd15a5b754f7e4863db0f1abf4ed278af74f2558
-
vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els14_armel.deb
sha:a7ad153e009f6687bc29de17c12f3c3d4b2f6a96
-
vim-nox_8.2.2434-3+deb11u3+tuxcare.els14_armel.deb
sha:f14b1acb1eb6ad687463379f3ae71024f5ea31a3
-
vim-tiny_8.2.2434-3+deb11u3+tuxcare.els14_armel.deb
sha:7cb8dc50836a9130d08cb1d63da112d55b0d0f0f
-
xxd_8.2.2434-3+deb11u3+tuxcare.els14_armel.deb
sha:8a67bdc20b7d13c431a6659def16f301999f69c8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.