[ubuntu/questing-updates] vim 2:9.1.0967-1ubuntu6.2 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Mon Apr 13 19:28:41 UTC 2026


vim (2:9.1.0967-1ubuntu6.2) questing-security; urgency=medium

  * SECURITY UPDATE: NULL pointer dereference in the NFA regex engine.
    - debian/patches/CVE-2026-32249.patch: Add range_endpoint and if checks
      in src/regexp_nfa.c. Add tests in src/testdir/test_regexp_utf8.vim.
    - CVE-2026-32249
  * SECURITY UPDATE: Command injection in glob.
    - debian/patches/CVE-2026-33412.patch: Add newline to SHELL_SPECIAL in
      src/os_unix.c.
    - CVE-2026-33412
  * SECURITY UPDATE: Security bypass in modeline.
    - debian/patches/CVE-2026-34982.patch: Disallow modeset while in secure
       mode in src/map.c and src/optiondefs.h.
    - CVE-2026-34982

Date: 2026-04-08 18:48:10.416220+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Questing-changes mailing list