[ubuntu/questing-security] vim 2:9.1.0967-1ubuntu6.8 (Accepted)
Kyle Kernick
kyle.kernick at canonical.com
Thu Jul 2 16:10:46 UTC 2026
vim (2:9.1.0967-1ubuntu6.8) questing-security; urgency=medium
* SECURITY UPDATE: Out-of-bounds write.
- debian/patches/CVE-2026-55693.patch: only descend while
depth < MAXWLEN - 1 in src/spellfile.c.
- debian/patches/CVE-2026-55892.patch: only descend while
depth < MAXWLEN - 1 in src/spell.c.
- CVE-2026-55693
- CVE-2026-55892
* SECURITY UPDATE: Code injection in local file deletion.
- debian/patches/CVE-2026-55895.patch: Use fnameescape() to escape
file name in runtime/autoload/netrw.vim.
- CVE-2026-55895
* SECURITY UPDATE: Out-of-bounds read with sodium encrypted files.
- debian/patches/CVE-2026-57452.patch: Verify that there is enough space
before function call in src/crypt.c.
- CVE-2026-57452
* SECURITY UPDATE: Out-of-bounds write with soundfold().
- debian/patches/CVE-2026-57455.patch: Add an abort condition to validate
buffer in src/spell.c.
- CVE-2026-57455
* SECURITY UPDATE: Code execution with python complete.
- debian/patches/CVE-2026-57456.patch: Use repr() to quote the doc strings
in runtime/autoload/python3complete.vim and ../pythoncomplete.vim.
- CVE-2026-57456
Date: 2026-06-30 20:58:29.577623+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.8
-------------- next part --------------
Sorry, changesfile not available.
More information about the Questing-changes
mailing list