[ubuntu/resolute-proposed] vim 2:9.1.2141-1ubuntu3 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Tue Apr 14 07:40:44 UTC 2026
vim (2:9.1.2141-1ubuntu3) resolute; urgency=medium
* SECURITY UPDATE: NULL pointer dereference in the NFA regex engine.
- debian/patches/CVE-2026-32249.patch: Add range_endpoint and if checks
in src/regexp_nfa.c. Add tests in src/testdir/test_regexp_utf8.vim.
- CVE-2026-32249
* SECURITY UPDATE: Command injection in glob.
- debian/patches/CVE-2026-33412.patch: Add newline to SHELL_SPECIAL in
src/os_unix.c.
- CVE-2026-33412
* SECURITY UPDATE: Command injection in tabpanel.
- debian/patches/CVE-2026-34714.patch: Add check_restricted check_secure
if check in src/autocmd.c. Add P_MLE in src/optiondefs.h. Add tests in
src/testdir/test_autocmd.vim and src/testdir/test_tabpanel.vim.
- CVE-2026-34714
* SECURITY UPDATE: Command injection in modeline.
- debian/patches/CVE-2026-34982.patch: Add check_secure in src/map.c. Add
P_MLE in src/optiondefs.h. Add tests in src/testdir/test_modeline.vim.
- debian/patches/CVE-2026-34982-post1.patch: Remove failing test and add
more s:modeline_fails in src/testdir/test_modeline.vim.
- CVE-2026-34982
Date: Tue, 31 Mar 2026 16:50:02 -0230
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/vim/2:9.1.2141-1ubuntu3
-------------- next part --------------
Format: 1.8
Date: Tue, 31 Mar 2026 16:50:02 -0230
Source: vim
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2:9.1.2141-1ubuntu3
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Changes:
vim (2:9.1.2141-1ubuntu3) resolute; urgency=medium
.
* SECURITY UPDATE: NULL pointer dereference in the NFA regex engine.
- debian/patches/CVE-2026-32249.patch: Add range_endpoint and if checks
in src/regexp_nfa.c. Add tests in src/testdir/test_regexp_utf8.vim.
- CVE-2026-32249
* SECURITY UPDATE: Command injection in glob.
- debian/patches/CVE-2026-33412.patch: Add newline to SHELL_SPECIAL in
src/os_unix.c.
- CVE-2026-33412
* SECURITY UPDATE: Command injection in tabpanel.
- debian/patches/CVE-2026-34714.patch: Add check_restricted check_secure
if check in src/autocmd.c. Add P_MLE in src/optiondefs.h. Add tests in
src/testdir/test_autocmd.vim and src/testdir/test_tabpanel.vim.
- CVE-2026-34714
* SECURITY UPDATE: Command injection in modeline.
- debian/patches/CVE-2026-34982.patch: Add check_secure in src/map.c. Add
P_MLE in src/optiondefs.h. Add tests in src/testdir/test_modeline.vim.
- debian/patches/CVE-2026-34982-post1.patch: Remove failing test and add
more s:modeline_fails in src/testdir/test_modeline.vim.
- CVE-2026-34982
Checksums-Sha1:
8cadbb0fc340fff48dcfbd923c575feefe67cb2c 3037 vim_9.1.2141-1ubuntu3.dsc
6b03f2aa83c3484976f08a95e94720b420927641 218476 vim_9.1.2141-1ubuntu3.debian.tar.xz
4e9c5370dafba960080b141acdee661cb4dc9fe3 17380 vim_9.1.2141-1ubuntu3_source.buildinfo
Checksums-Sha256:
21b7e9cb8c017545b369f43ccdff588d9c925b949badbcb292e969c9fe7f6e80 3037 vim_9.1.2141-1ubuntu3.dsc
5373ccad9744cbb59818b644ea6ba766ebc7b19eb5ea02ea58c3cd8e157983c7 218476 vim_9.1.2141-1ubuntu3.debian.tar.xz
9eb1b59e1d3801b2cadb0271cd9abec64549402a2671fbd0582f3df1c6b1e6e9 17380 vim_9.1.2141-1ubuntu3_source.buildinfo
Files:
4f193466d749e41a2e0894ae5e56f3bc 3037 editors optional vim_9.1.2141-1ubuntu3.dsc
149aeb55db1bfde98e0e4e1955eb0b71 218476 editors optional vim_9.1.2141-1ubuntu3.debian.tar.xz
f727ed46f81eef1facaacfc278fcd1b7 17380 editors optional vim_9.1.2141-1ubuntu3_source.buildinfo
Original-Maintainer: Debian Vim Maintainers <team+vim at tracker.debian.org>
More information about the Resolute-changes
mailing list