[CLSA-2026:1785426678] vim: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-30 15:51:33 UTC
Description:
- CVE-2022-0213: bound the space appended to the window status line so it cannot be written past the end of NameBuff - CVE-2024-43802: check that the typeahead buffer has room before advancing the offset when flushing mapped characters - CVE-2026-28422: account for the byte length of a multi-byte fill character when sizing the status line buffer and when padding item groups - CVE-2022-0351: limit expression recursion depth so a deeply nested condition cannot exhaust the stack
Updated packages:
  • vim-X11-8.2.2637-22.el9_6.1.tuxcare.els40.x86_64.rpm
    sha:c15560eec9f24892352a78e7f2dadfe7800fc77000d73d817b5838008848ca4c
  • vim-common-8.2.2637-22.el9_6.1.tuxcare.els40.x86_64.rpm
    sha:37cab917049c9b4f04309c38e136cde512789c98209c4597dd0081a1c10c57c6
  • vim-enhanced-8.2.2637-22.el9_6.1.tuxcare.els40.x86_64.rpm
    sha:c201554959a9ee51f5b7cedb413e1cd27c17e43947acdf9c62aedc0f3d4a14a1
  • vim-filesystem-8.2.2637-22.el9_6.1.tuxcare.els40.noarch.rpm
    sha:6be8b12a04f81956cd7447848c99347274f72304eed02639b0c28b45dea237d4
  • vim-minimal-8.2.2637-22.el9_6.1.tuxcare.els40.x86_64.rpm
    sha:f401fa8012ea5fe994b7a797fcc57771944c53f84af6e7d5f346e549c4dd7919
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.