[ubuntu/noble-security] vim 2:9.1.0016-1ubuntu7.18 (Accepted)

Kyle Kernick kyle.kernick at canonical.com
Tue Jul 14 15:56:43 UTC 2026


vim (2:9.1.0016-1ubuntu7.18) noble-security; urgency=medium

  * SECURITY UPDATE: Command execution in PHP omni-completion.
    - debian/patches/CVE-2026-59856.patch: Quote the class name before
      inserting it into the search() in runtime/autoload/phpcomplete.vim
    - CVE-2026-59856
  * SECURITY UPDATE: Stack out-of-bounds write in spell_soundfold_sal().
    - debian/patches/CVE-2026-59857.patch: Bound the single-byte SAL result
      writes in src/spell.c
    - CVE-2026-59857
  * SECURITY UPDATE: Arbitrary command execution during C omni-completion.
    - debian/patches/CVE-2026-59858.patch: Escape the type field before
      inserting it into pattern in runtime/autoload/ccomplete.vim
    - CVE-2026-59858

Date: 2026-07-13 20:19:11.871773+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.18
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list