[CLSA-2026:1785846808] vim: Fix of CVE-2026-41411
Type:
security
Severity:
Important
Release date:
2026-08-04 12:33:39 UTC
Description:
- CVE-2026-41411: fix OS command injection in tag file processing by disallowing backticks in the filename field before wildcard expansion (upstream 9.2.0357)
CVEs fixed:
Updated packages:
  • vim-X11-7.4.629-8.0.1.el7_9.tuxcare.els19.x86_64.rpm
    sha:4f4c02362bc06092f4c7613adbb8ddfc1205009786c5a0977205c7c5b17fca2e
  • vim-common-7.4.629-8.0.1.el7_9.tuxcare.els19.x86_64.rpm
    sha:0e5aa36f4b5831f56f540cae009786c5b61c81496a95a34e066c80ea161d8ffe
  • vim-enhanced-7.4.629-8.0.1.el7_9.tuxcare.els19.x86_64.rpm
    sha:dceeefe2cec04a59d47f293bbfb60f9bbf225a8361cea03931f6b675add44077
  • vim-filesystem-7.4.629-8.0.1.el7_9.tuxcare.els19.x86_64.rpm
    sha:debbe3099e228bd627340b54ca95f2466150e4943e87dd342cab3b3ff0a9e79b
  • vim-minimal-7.4.629-8.0.1.el7_9.tuxcare.els19.x86_64.rpm
    sha:c548606cd1f57ed369e5e731048ada67a3e9192c5d9f7c2f159749f20a375cfc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.