[CLSA-2026:1784799614] vim: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-23 09:40:42 UTC
Description:
- CVE-2026-59856: arbitrary command execution in PHP omni-completion; a class/trait name from the edited buffer was interpolated unescaped into a search() pattern run via win_execute(), letting a single quote plus | inject Ex commands (:!); quote the name with string() (runtime/autoload/phpcomplete.vim). Adds a functional test.
Updated packages:
  • vim-X11-9.0.2153-1.amzn2.0.7.tuxcare.els4.x86_64.rpm
    sha:4397b9ad7065d3172f3a7afa56725803c61b470e5aad0fc02742084233ef0fa1
  • vim-common-9.0.2153-1.amzn2.0.7.tuxcare.els4.x86_64.rpm
    sha:e485e27192324291f7dea1dceecdec8e1706da882dc313a7d5c302651e46431d
  • vim-data-9.0.2153-1.amzn2.0.7.tuxcare.els4.noarch.rpm
    sha:6fb0fc1e6c4bb8b7b7afa3aa1513981aba717d7c4ccb3170c36ad3aca738ba76
  • vim-enhanced-9.0.2153-1.amzn2.0.7.tuxcare.els4.x86_64.rpm
    sha:ce1857ab9a0281510a092d85a836f8a6e1114905a3f80b39ac5478e82bb245b4
  • vim-filesystem-9.0.2153-1.amzn2.0.7.tuxcare.els4.noarch.rpm
    sha:1a690f8efb426c6daa58eb8f3a9dd38f70036729b796333be0ceda27fcb7c105
  • vim-minimal-9.0.2153-1.amzn2.0.7.tuxcare.els4.x86_64.rpm
    sha:a9a53319840ecbf79297a620b6dbbe9ad723053fec731c1e619239ebd14cd7cc
  • xxd-9.0.2153-1.amzn2.0.7.tuxcare.els4.x86_64.rpm
    sha:181d919a7484c14454b487d8543dc21018afc09817ac19eca9a70b8593f3dd58
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.