[CLSA-2026:1781081927] vim: Fix of CVE-2026-41411
Type:
security
Severity:
Important
Release date:
2026-06-10 08:59:02 UTC
Description:
- CVE-2026-41411: fix command injection via backticks in tag file filenames by disallowing backtick expansion in expand_tag_fname() (src/tag.c, upstream patch 9.2.0357)
CVEs fixed:
Updated packages:
  • vim-X11-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:02a769823af27e2ae27c907e7e17a4e6bbfacc0b509622fb52a795df896cd4bb
  • vim-common-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:6423e3c49566510a6fca714654a8b9e44b9f147e042208a1c2d36af96978766e
  • vim-enhanced-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:3e05637de6804b31006e4e72036965f706d5aedffc806ca204752433485ce94f
  • vim-filesystem-8.0.1763-16.el8.tuxcare.els18.noarch.rpm
    sha:5ff025d323a9beed7d7bb7a21447c90e547919e885e19353e317b5769903f740
  • vim-minimal-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:e362625133f2494dc34c5610d6bb932de1b455fc32c182ac182b3a613a960ca1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.