[CLSA-2026:1789639975] Fix of 20 CVEs
Type:
security
Severity:
Critical
Release date:
2026-09-17 10:13:19 UTC
Description:
* SECURITY UPDATE: with latin1 encoding CTRL-W might go before the start of the command line - debian/patches/CVE-2022-1619.patch: with latin1 encoding CTRL-W might go before the start of the command line - CVE-2022-1619 * SECURITY UPDATE: using an invalid index when looking for spell suggestions - debian/patches/CVE-2022-2126.patch: using an invalid index when looking for spell suggestions - CVE-2022-2126 * SECURITY UPDATE: reading beyond the end of the line with lisp indenting - debian/patches/CVE-2022-2183.patch: reading beyond the end of the line with lisp indenting - CVE-2022-2183 * SECURITY UPDATE: reading past the end of a string with some completions - debian/patches/CVE-2022-2286.patch: reading past the end of a string with some completions - CVE-2022-2286 * SECURITY UPDATE: reading past the end of a completion with a long line and 'infercase' set - debian/patches/CVE-2022-2343.patch: reading past the end of a completion with a long line and 'infercase' set - CVE-2022-2343 * SECURITY UPDATE: illegal memory access when a pattern starts with an illegal byte - debian/patches/CVE-2022-2581.patch: illegal memory access when a pattern starts with an illegal byte - CVE-2022-2581 * SECURITY UPDATE: using freed memory with an error in an assert argument - debian/patches/CVE-2022-2817.patch: using freed memory with an error in an assert argument - CVE-2022-2817 * SECURITY UPDATE: using freed memory when an autocommand changes a mark - debian/patches/CVE-2022-3256.patch: using freed memory when an autocommand changes a mark - CVE-2022-3256 * SECURITY UPDATE: buffer underflow with an unexpected :finally - debian/patches/CVE-2022-3296.patch: buffer underflow with an unexpected :finally - CVE-2022-3296 * SECURITY UPDATE: missing NULL check on the return value of XChangeGC() - debian/patches/CVE-2022-47024.patch: missing NULL check on the return value of XChangeGC() - CVE-2022-47024 * SECURITY UPDATE: invalid memory access with a bad 'statusline' value - debian/patches/CVE-2023-0049.patch: invalid memory access with a bad 'statusline' value - CVE-2023-0049 * SECURITY UPDATE: buffer overflow in netbeans special_keys() handling - debian/patches/CVE-2026-26269.patch: buffer overflow in netbeans special_keys() handling - CVE-2026-26269 * SECURITY UPDATE: insufficient validation of hostname and port in netrw URIs allows command injection - debian/patches/CVE-2026-28417.patch: insufficient validation of hostname and port in netrw URIs allows command injection - CVE-2026-28417 * SECURITY UPDATE: netbeans defineAnnoType and specialKeys pass unvalidated names into Ex commands, allowing command injection - debian/patches/CVE-2026-39881.patch: netbeans defineAnnoType and specialKeys pass unvalidated names into Ex commands, allowing command injection - CVE-2026-39881 * SECURITY UPDATE: command injection via backticks in tag files - debian/patches/CVE-2026-41411.patch: command injection via backticks in tag files - CVE-2026-41411 * SECURITY UPDATE: possible code execution with python3complete and pythoncomplete - debian/patches/CVE-2026-52858.patch: possible code execution with python3complete and pythoncomplete - CVE-2026-52858 * SECURITY UPDATE: out-of-bounds read in update_snapshot() with a full combining-character cell - debian/patches/CVE-2026-52859.patch: out-of-bounds read in update_snapshot() with a full combining-character cell - CVE-2026-52859 * SECURITY UPDATE: out-of-bounds write with soundfold() - debian/patches/CVE-2026-57455.patch: out-of-bounds write with soundfold() - CVE-2026-57455 * SECURITY UPDATE: code execution via a crafted .VimballRecord file - debian/patches/CVE-2026-73076.patch: code execution via a crafted .VimballRecord file - CVE-2026-73076
Updated packages:
  • vim_8.2.2434-3+deb11u3+tuxcare.els11_amd64.deb
    sha:d2e821e2307768f85f4091272f5f7c3df46364a8
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els11_amd64.deb
    sha:4157aa7476cb73780d9eade89521726c22ae9612
  • vim-common_8.2.2434-3+deb11u3+tuxcare.els11_all.deb
    sha:63abac974762cccd9ae4fb52242b688d8915f62c
  • vim-doc_8.2.2434-3+deb11u3+tuxcare.els11_all.deb
    sha:db5970c16ad72fdeb25d1d15182bbb27df8aa263
  • vim-gtk_8.2.2434-3+deb11u3+tuxcare.els11_all.deb
    sha:7e611393689506ee852ef580044494d353857c81
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els11_amd64.deb
    sha:1761724b65273b840d6f4d840a5a94bf75629528
  • vim-gui-common_8.2.2434-3+deb11u3+tuxcare.els11_all.deb
    sha:89b6da832ca02dbde41a077834eb37781e9e0afb
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els11_amd64.deb
    sha:c7addd609805665eb8c2b006b84f44ed1cd7a503
  • vim-runtime_8.2.2434-3+deb11u3+tuxcare.els11_all.deb
    sha:091a0b3ec76b7d8c1abcd880be0b20f1d1c62a6c
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els11_amd64.deb
    sha:5eb4ed40afc8a50b5f1c0f6e6ff353eaece3088c
  • xxd_8.2.2434-3+deb11u3+tuxcare.els11_amd64.deb
    sha:ac293cfa105969d2241acb2d2ab10c5efd3ebaf1
  • vim_8.2.2434-3+deb11u3+tuxcare.els11_arm64.deb
    sha:3d8cecf44133208f6f82dfa43f9d84ee84a24c70
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els11_arm64.deb
    sha:8f45b8435d38f9fa6d901450fcfcf68d51ffc31b
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els11_arm64.deb
    sha:717a9374b0b6e23a01a923ef458d5e6bed63700a
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els11_arm64.deb
    sha:8af2edd3cd6fa6501e71bdd97732ac13cc54695a
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els11_arm64.deb
    sha:28814bc781429015b3b268dbc635029630182762
  • xxd_8.2.2434-3+deb11u3+tuxcare.els11_arm64.deb
    sha:c8747ddf02fb7efa98c1a42465663cbc77885efb
  • vim_8.2.2434-3+deb11u3+tuxcare.els11_armel.deb
    sha:62281f576b9aafbe064b63698c4eee2cd92bd619
  • vim-athena_8.2.2434-3+deb11u3+tuxcare.els11_armel.deb
    sha:5ae96f2155da2a7784e1c82921383d0230446a55
  • vim-gtk3_8.2.2434-3+deb11u3+tuxcare.els11_armel.deb
    sha:42753d84346c575c9d918b794c1ac45e5edb86c2
  • vim-nox_8.2.2434-3+deb11u3+tuxcare.els11_armel.deb
    sha:6256e7a2b4b607f1400df2ead038af717b0bb097
  • vim-tiny_8.2.2434-3+deb11u3+tuxcare.els11_armel.deb
    sha:befbf15ecdea425ce309e712037595d574c1df5d
  • xxd_8.2.2434-3+deb11u3+tuxcare.els11_armel.deb
    sha:1e69c1bbd3fa8c3569be8a7fc61b488d4d4b260b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.