{"id":"CLSA-2026-1777544441","summary":"vim: Fix of 13 CVEs","details":"- CVE-2021-3796: fix use-after-free in nv_replace by getting the\n  line pointer again after ins_copychar may have released it\n- CVE-2021-3973: fix heap buffer overflow in\n  find_file_in_path_option by rejecting len == 0 inputs\n- CVE-2022-0413: fix use-after-free in do_sub when the substitute\n  string is a \"\\=\" expression by copying the string before eval\n- CVE-2022-0943: fix heap overflow in spell_suggest when \"z=\" in\n  Visual mode by clamping badlen to the remaining line length\n- CVE-2022-1620: fix NULL pointer access by guarding both\n  vim_regexec calls in fname_match and the second fname_match\n  call in buflist_match against rmp-\u003eregprog becoming NULL after\n  the AUTOMATIC_ENGINE fallback fails to recompile the pattern\n- CVE-2022-1796: fix use-after-free in find_pattern_in_path by\n  making a copy of the identifier pointer before the call\n- CVE-2022-2207: fix read-before-start-of-line in ins_bs by\n  requiring w_cursor.col \u003e 0 in the whitespace back-step loop\n- CVE-2022-3235: fix use-after-free in cmdline input-method\n  handling by tracking the owning buffer and checking buf_valid\n- CVE-2022-3296: fix buffer underflow in ex_finally by searching\n  for a valid CSF_TRY frame before accessing cs_flags\n- CVE-2023-46246: fix integer overflow in :history by clamping\n  long values to INT_MAX before casting to int\n- CVE-2023-48231: fix use-after-free in win_close by returning\n  early when the window is no longer valid after BufLeave\n- CVE-2023-48706: fix use-after-free in ex_substitute by always\n  allocating sub and freeing it on every exit path\n- CVE-2026-33412: fix command injection via newline in glob() by\n  adding '\\n' to the SHELL_SPECIAL escape set","modified":"2026-06-01T00:33:18.631626219Z","published":"2026-05-02T01:09:10Z","upstream":["CVE-2021-3796","CVE-2021-3973","CVE-2022-0413","CVE-2022-0943","CVE-2022-1620","CVE-2022-1796","CVE-2022-2207","CVE-2022-3235","CVE-2022-3296","CVE-2023-46246","CVE-2023-48231","CVE-2023-48706","CVE-2026-33412"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/centos7els/CLSA-2026-1777544441.html"}],"affected":[{"package":{"name":"vim-X11","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/vim-X11?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:7.4.629-8.0.1.el7_9.tuxcare.els11"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1777544441.json"}},{"package":{"name":"vim-common","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/vim-common?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:7.4.629-8.0.1.el7_9.tuxcare.els11"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1777544441.json"}},{"package":{"name":"vim-enhanced","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/vim-enhanced?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:7.4.629-8.0.1.el7_9.tuxcare.els11"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1777544441.json"}},{"package":{"name":"vim-filesystem","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/vim-filesystem?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:7.4.629-8.0.1.el7_9.tuxcare.els11"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1777544441.json"}},{"package":{"name":"vim-minimal","ecosystem":"TuxCare:CentOS:7","purl":"pkg:rpm/tuxcare/vim-minimal?distro=centos-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2:7.4.629-8.0.1.el7_9.tuxcare.els11"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos7els/CLSA-2026-1777544441.json"}}],"schema_version":"1.7.5"}