[CLSA-2026:1777944852] vim: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-05 01:34:18 UTC
Description:
- CVE-2021-3984: in find_start_brace() (misc1.c), when a found '{' lies inside a comment, restore the full cursor position (line and column) instead of only the line so subsequent C-indent lookups stay within the line bounds. - CVE-2022-2571: in ins_compl_get_exp() (edit.c), when CONT_ADDING is active, only advance tmp_ptr by compl_length if compl_length does not exceed the remaining line length, so insert-mode completion no longer reads past the end of the line.
Updated packages:
  • vim-X11-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:6a3423032792b36000e6dabec5d6cedd8f75d17d79ca14f65b6769d19efc6e22
  • vim-common-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:282e93e1ef6dafbce9218a100b9bc2dd55bae0f851700dd1e502c1642963c8d9
  • vim-enhanced-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:6d6c98225b28073c1ef77e9bf8784e78e5bc04819afe3ca085bf56ea5419c225
  • vim-filesystem-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:e403ca4eb7a7e75b2883304cd609c5f67ac178ea89c5b8ad82e341ac55347911
  • vim-minimal-7.4.629-8.0.1.el7_9.tuxcare.els13.x86_64.rpm
    sha:deecb63fd0e72d7926ef8e922f921e8b1d2290c6128bdffe45183b6dfcb0f980
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.