[CLSA-2026:1787679179] Fix CVE(s): CVE-2022-3520
Type:
security
Severity:
Critical
Release date:
2026-08-25 17:33:09 UTC
Description:
* SECURITY UPDATE: out-of-bounds read after a Visual block put: do_put() set the '] mark as bd.textcol + totlen - 1 without a lower bound, so a blockwise register whose lines are all empty (y_width becomes -1 in str_to_reg(), giving totlen 0) left the column at -1. With 'selection' set to exclusive, nv_put() then passed that mark to inc(), which dereferenced a pointer before the start of the line buffer. - debian/patches/CVE-2022-3520.patch: clamp curbuf->b_op_end.col to 0 in src/ops.c; matches upstream patch 9.0.0765. - CVE-2022-3520
CVEs fixed:
Updated packages:
  • vim_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
    sha:5669938ebd2d34ce1396c8c6d0dd0c8b41c2a187
  • vim-athena_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
    sha:5efc4ec97ba3b5c8a1dd26c510a874b9e7064430
  • vim-common_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
    sha:490e48fbbaa4b71f84c7432093957b381a8f60fd
  • vim-doc_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
    sha:7ac1df882faf985aa24d7d13111437d4f3a7656c
  • vim-gnome_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
    sha:34e18ba35074b3ce3c6d547e72f37b8c35af5ef1
  • vim-gtk_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
    sha:d5468aa7f96c8a367abd4d0f85cc8e26d768344f
  • vim-gtk3_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
    sha:0566a30ab7c42de7d7e77e281886954ba34691ce
  • vim-gui-common_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
    sha:72aeb128e77baff01d9ab508506d130813be84ae
  • vim-nox_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
    sha:b41bd98f401764734948a4550fae9f8ca705a5af
  • vim-runtime_8.0.1453-1ubuntu1.13+tuxcare.els4_all.deb
    sha:61051db5d7177ae1b64c541ba0f8a5ef0750f5ae
  • vim-tiny_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
    sha:a3be8919aad37637a98d7e28b3dc4e3dee550329
  • xxd_8.0.1453-1ubuntu1.13+tuxcare.els4_amd64.deb
    sha:0b9a65c2e4e97ad3fcdbc09ea8caf4cf5adff662
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.