[CLSA-2026:1784799471] vim: Fix of CVE-2026-59858
Type:
security
Severity:
Important
Release date:
2026-07-23 09:38:17 UTC
Description:
- CVE-2026-59858: fix arbitrary Ex command execution during C omni-completion; the typeref/typename tag field was interpolated unescaped into a :vimgrep pattern run via :execute, letting a crafted tags file close the pattern and append an Ex command; escape the type field with escape(typename, '/\') (runtime/autoload/ccomplete.vim, upstream patch 9.2.0735)
CVEs fixed:
Updated packages:
  • vim-X11-8.0.1763-19.el8.4.tuxcare.els22.x86_64.rpm
    sha:c64958b8f25eec6cfb86803d7b00556e5bd7808a15de3a2fa6edc3d95489b276
  • vim-common-8.0.1763-19.el8.4.tuxcare.els22.x86_64.rpm
    sha:bab8cc734aa92efc09f94ad163e9c2e9d002431774725cb496890eedcc083a30
  • vim-enhanced-8.0.1763-19.el8.4.tuxcare.els22.x86_64.rpm
    sha:e02f4cb5f9ec863b001b68c3cb0f04a716adce7397ad236b0d282874f09d4090
  • vim-filesystem-8.0.1763-19.el8.4.tuxcare.els22.noarch.rpm
    sha:5deb2f7963ad31767c5bdcfc4de1a9d233c5791f4a430bcc6b60a9e502579f8e
  • vim-minimal-8.0.1763-19.el8.4.tuxcare.els22.x86_64.rpm
    sha:2e4006b9a949c1c4b82aff1fa070f153cd3a3e525e85cbde406c1ec0c96f99ef
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.