[CLSA-2026:1786454677] vim: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-11 13:24:50 UTC
Description:
- CVE-2026-34982: fix modeline sandbox bypass leading to arbitrary OS command execution — add the 'modelineexpr' option and the P_MLE flag, and set P_MLE on the expression-evaluating options including complete/guitabtooltip/printheader (upstream 9.2.0276 with the 8.1.1366 modelineexpr prerequisite)
Updated packages:
  • vim-X11-7.4.629-5.2.el6.tuxcare.els62.x86_64.rpm
    sha:bfa607df707d6e039c742e52e90c9cf17248997ea8113c5e211d6ecd868fd0b4
  • vim-common-7.4.629-5.2.el6.tuxcare.els62.x86_64.rpm
    sha:df6514eac331b83b4c0d6ba223671b8827485c2571b2affd8c90181d8dfc5fe0
  • vim-enhanced-7.4.629-5.2.el6.tuxcare.els62.x86_64.rpm
    sha:fd15ccc4db1d59b08c1299544e98f9fe6cb7993e1053ae6c3739b7670d0ccfba
  • vim-filesystem-7.4.629-5.2.el6.tuxcare.els62.x86_64.rpm
    sha:479a059c2e09977b65db0e60ac4b54dccc82ebbf4e41afe18f2dccad582766e3
  • vim-minimal-7.4.629-5.2.el6.tuxcare.els62.x86_64.rpm
    sha:a45564930ed58e9979fa189366c10a5608d21ce514265315019646bb2fcdd4c5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.