[CLSA-2026:1777945409] vim: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-05 23:31:50 UTC
Description:
- CVE-2021-3984: in find_start_brace() (misc1.c), when a found '{' lies inside a comment, restore the full cursor position (line and column) instead of only the line so subsequent C-indent lookups stay within the line bounds. - CVE-2022-2571: in ins_compl_get_exp() (edit.c), when CONT_ADDING is active, only advance tmp_ptr by compl_length if compl_length does not exceed the remaining line length, so insert-mode completion no longer reads past the end of the line.
Updated packages:
  • vim-X11-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:9273c79f9c69b96ee9307c0430eb68b8baeb842c700502ebb496ec27bcee1de9
  • vim-common-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:89f6fc7b215c5018c63481bb453133d1d701edacdcb37531c411f1319c564408
  • vim-enhanced-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:d8e143c67d43723f1cb27057237a3ae8a4e482f152d9277e023a89afdbb5a383
  • vim-filesystem-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:1ae129257fa2da03bd8282329075c1d1f22b69835f4c30dc7d52205c0df227f2
  • vim-minimal-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:72626aa3167320c59d7b5642ec1a0e0afb5cd5aeaf1a9cff21c2d753a9985312
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.