[CLSA-2026:1786353169] vim: Fix of CVE-2026-59858
Type:
security
Severity:
Important
Release date:
2026-08-13 12:41:30 UTC
Description:
- CVE-2026-59858: escape the typeref/typename tags field before interpolating it into the :vimgrep pattern in ccomplete.vim s:StructMembers(), preventing arbitrary Ex command execution during C omni-completion (upstream 9.2.0735)
CVEs fixed:
Updated packages:
  • vim-X11-7.4.629-8.0.1.el7_9.tuxcare.els25.x86_64.rpm
    sha:81da533159e8846bdee11e4aa20181e678d491732f6668079951b1ce5850134d
  • vim-common-7.4.629-8.0.1.el7_9.tuxcare.els25.x86_64.rpm
    sha:7b895dad6bb2579f1c2eb533f40b08d7a55ed1158b958b2b4718b14d90384ffc
  • vim-enhanced-7.4.629-8.0.1.el7_9.tuxcare.els25.x86_64.rpm
    sha:d83385bbcbe690a46d04ef26220a50ac2d1f58ed2699440cd718cc54802ce2c1
  • vim-filesystem-7.4.629-8.0.1.el7_9.tuxcare.els25.x86_64.rpm
    sha:01a448776a1d1f6236a5550281b453f78c8c7823d87ecfd5825e3b98e21729ff
  • vim-minimal-7.4.629-8.0.1.el7_9.tuxcare.els25.x86_64.rpm
    sha:4ae613d2980ab4b488f39ec2bbd09213bb168984d603d78d8d160d64d3dccfe3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.