Release date:
2026-07-23 09:54:34 UTC
Description:
- CVE-2026-59857: bound the single-byte SAL result writes and the
terminating NUL to MAXWLEN - 1 in spell_soundfold_sal() to prevent a
stack out-of-bounds write with a crafted spell file
(src/spell.c, upstream vim 9.2.0725)
Updated packages:
-
vim-X11-8.2.2637-22.el9_6.1.tuxcare.els39.x86_64.rpm
sha:9632758e54a1dd0808145cc3769ba07892fe2dc3d29a663e3c8d60f68851b578
-
vim-common-8.2.2637-22.el9_6.1.tuxcare.els39.x86_64.rpm
sha:a418587a4ecb56ba05fb36972103a7e7fe4164e57af1e86be965fa7570f60dd9
-
vim-enhanced-8.2.2637-22.el9_6.1.tuxcare.els39.x86_64.rpm
sha:71eb356e449a6a462dfc0759810b6ac2a404448a67545cae09b22f9a3588c421
-
vim-filesystem-8.2.2637-22.el9_6.1.tuxcare.els39.noarch.rpm
sha:432fdc4bd52f8fe0ced23e8358da45537d6667b3422856c13411789f4b4c7133
-
vim-minimal-8.2.2637-22.el9_6.1.tuxcare.els39.x86_64.rpm
sha:480c976fbcd9ccbb246ac7bcb3342023bdfdc9725ccbc609bc6d144f1e50ec15
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.