Release date:
2026-08-25 17:33:09 UTC
Description:
* SECURITY UPDATE: out-of-bounds read after a Visual block put: do_put()
set the '] mark as bd.textcol + totlen - 1 without a lower bound, so a
blockwise register whose lines are all empty (y_width becomes -1 in
str_to_reg(), giving totlen 0) left the column at -1. With 'selection'
set to exclusive, nv_put() then passed that mark to inc(), which
dereferenced a pointer before the start of the line buffer.
- debian/patches/CVE-2022-3520.patch: clamp curbuf->b_op_end.col to 0 in
src/ops.c; matches upstream patch 9.0.0765.
- CVE-2022-3520
Updated packages:
-
vim_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
sha:5669938ebd2d34ce1396c8c6d0dd0c8b41c2a187
-
vim-athena_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
sha:5efc4ec97ba3b5c8a1dd26c510a874b9e7064430
-
vim-common_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
sha:490e48fbbaa4b71f84c7432093957b381a8f60fd
-
vim-doc_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
sha:7ac1df882faf985aa24d7d13111437d4f3a7656c
-
vim-gnome_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
sha:34e18ba35074b3ce3c6d547e72f37b8c35af5ef1
-
vim-gtk_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
sha:d5468aa7f96c8a367abd4d0f85cc8e26d768344f
-
vim-gtk3_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
sha:0566a30ab7c42de7d7e77e281886954ba34691ce
-
vim-gui-common_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
sha:72aeb128e77baff01d9ab508506d130813be84ae
-
vim-nox_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
sha:b41bd98f401764734948a4550fae9f8ca705a5af
-
vim-runtime_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
sha:61051db5d7177ae1b64c541ba0f8a5ef0750f5ae
-
vim-tiny_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
sha:a3be8919aad37637a98d7e28b3dc4e3dee550329
-
xxd_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
sha:0b9a65c2e4e97ad3fcdbc09ea8caf4cf5adff662
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.