Release date:
2026-07-23 10:23:11 UTC
Description:
- CVE-2026-59858: fix arbitrary Ex command execution during C omni-completion; the typeref/typename tag field was interpolated unescaped into a :vimgrep pattern run via :execute, letting a crafted tags file close the pattern and append an Ex command; escape the type field with escape(typename, '/\') (runtime/autoload/ccomplete.vim, upstream patch 9.2.0735)
Updated packages:
-
vim-X11-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
sha:ab920a0e01f9a5ed09ca7dd61564aa40747add1aae82cb7129e1f843b7cd43c1
-
vim-common-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
sha:895c3c21dc033301cdad103afc9729e8eecb5ce6756e0678b79b2abc342383f5
-
vim-enhanced-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
sha:c54f880aaeb4e002b43b149fa7c9309d5f2fc5d07ad7098b936daded4719d690
-
vim-filesystem-8.0.1763-16.el8.tuxcare.els23.noarch.rpm
sha:eca0dc59cd0e57b2e0c4eb3355e60156dda1ba2a490ca6f4e76103be8ec30f49
-
vim-minimal-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
sha:5c3e4e89a906170ee7cfc2c3847c6f01868255c16b034ee97a96ac6c8255bb00
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.