[CLSA-2026:1779583625] vim: Fix of CVE-2026-46483
Type:
security
Severity:
Important
Release date:
2026-05-25 07:25:53 UTC
Description:
- CVE-2026-46483: fix command injection in tar plugin Vimuntar() when decompressing .tgz archives by passing the {special} flag to shellescape() (upstream vim 9.2.0479)
Updated packages:
  • vim-X11-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:42c3a506a199f24efd1a80011a7234d3a67e30b6375da59df1404de2f1ecbe4b
  • vim-common-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:1942f33c23ad649015fd7b3cc7f7c729ecbd7abde90c2f2201098f64d8007bed
  • vim-enhanced-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:bbd683b92ba8bf1cf96866237baea1fab49ea5e64648510f04bfb1c690138408
  • vim-filesystem-8.0.1763-16.el8.tuxcare.els17.noarch.rpm
    sha:8f582f83a1beb87bcd3f0fd0c9bdabfdd04d7dff628878b39193b328a7373fe6
  • vim-minimal-8.0.1763-16.el8.tuxcare.els17.x86_64.rpm
    sha:eb9479acef617e93c8ae29f49a09c4cec7269f0638cb7f21b1d5246e5f0a1f68
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.