[CLSA-2026:1784799349] vim: Fix of CVE-2026-59858
Type:
security
Severity:
Important
Release date:
2026-07-23 09:36:15 UTC
Description:
- CVE-2026-59858: fix arbitrary Ex command execution during C omni-completion; the typeref/typename tag field was interpolated unescaped into a :vimgrep pattern run via :execute, letting a crafted tags file close the pattern and append an Ex command; escape the type field with escape(typename, '/\') (runtime/autoload/ccomplete.vim, upstream patch 9.2.0735)
CVEs fixed:
Updated packages:
  • vim-X11-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
    sha:79e7f0fc8782f012f8edfd54c736af159bd565c6b8d059dd88fc352e5ba1b1fc
  • vim-common-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
    sha:9bf3790c8a7eed849674666f22f98d07b2f15dc9c56e6cc67cf00b57e45767dd
  • vim-enhanced-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
    sha:c2e0f2998acdeb1a8b379d53102b7e4e35fc5ad8573c878e866b602d0906c34b
  • vim-filesystem-8.0.1763-16.el8.tuxcare.els23.noarch.rpm
    sha:3b9f2cda01e0dd7925c18c537826e276a21c86515bedb3a1a02a47778a4cf7a3
  • vim-minimal-8.0.1763-16.el8.tuxcare.els23.x86_64.rpm
    sha:9c03086b6837b62ce4dbf415129b937f75afaecce9972af99e96ba2fd8730250
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.