[CLSA-2026:1781082148] vim: Fix of CVE-2026-41411
Type:
security
Severity:
Important
Release date:
2026-06-10 09:02:50 UTC
Description:
- CVE-2026-41411: fix command injection via backticks in tag file filenames by disallowing backtick expansion in expand_tag_fname() (src/tag.c, upstream patch 9.2.0357)
CVEs fixed:
Updated packages:
  • vim-X11-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:00a5b374a4e062d32d9277bc4edbdc7c1da5652b3f8917b97ced0e36b514e72a
  • vim-common-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:9c0b7c7e134bacc206654b1b0f9df814663c2039fc19f4c2d65fcf0a8abc93dc
  • vim-enhanced-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:46934410938faf16ba4499330dfab669b84b96bb99fff81908d1cd45a491a5b8
  • vim-filesystem-8.0.1763-16.el8.tuxcare.els18.noarch.rpm
    sha:2b8f708fc7e949afe3a080c760c62050f88674398f69b88df3c47999f5224982
  • vim-minimal-8.0.1763-16.el8.tuxcare.els18.x86_64.rpm
    sha:bee47d0fb7e7b78890a7e77e0965da87937f3ca32c519f92a8c63b8e3bb62a50
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.